Life Sciences & Healthcare · SAP Consulting

SAP CSV & GxP
Compliance

100 knowledge cards across 4 compliance domains

Global SAP GxP & CSV · China Compliance in GxP & CSV · SAP S/4HANA Cloud (PCE) · Architecture & Toolset

Prepared by Mark & Xincheng · April 2026

SAP CSV & GxP in LSHC

Project Wiki for Regulatory Compliance prepared by Mark & Xincheng, April 2026

Global SAP GxP & CSV

What is the primary goal of Computer System Validation (CSV) in SAP projects?

Click to Reveal

Global SAP GxP & CSV

To provide documented evidence that the SAP system consistently performs according to its intended use and meets GxP regulatory requirements.

Click to Flip Back

Global SAP GxP & CSV

Explain the relationship between CSV and GxP.

Click to Reveal

Global SAP GxP & CSV

CSV is the process used to ensure that computerized systems (like SAP) comply with GxP (Good Practice) regulations, such as GMP, GDP, and GCP.

Click to Flip Back

Global SAP GxP & CSV

What is the 'V-Model' in the context of SAP CSV?

Click to Reveal

Global SAP GxP & CSV

A SDLC framework that maps requirements (User Requirements, Functional Specs) directly to their corresponding testing phases (IQ, OQ, PQ).

Click to Flip Back

Global SAP GxP & CSV

What does GAMP 5 stand for, and why is it important?

Click to Reveal

Global SAP GxP & CSV

Good Automated Manufacturing Practice (Version 5); it is the industry-standard risk-based approach for compliant GxP computerized systems.

Click to Flip Back

Global SAP GxP & CSV

How does CSV impact the SAP Blueprinting phase?

Click to Reveal

Global SAP GxP & CSV

It requires the early definition of User Requirements (URS) and a Risk Assessment to determine which SAP processes are GxP-relevant.

Click to Flip Back

Global SAP GxP & CSV

What are the common pitfalls in SAP CSV projects?

Click to Reveal

Global SAP GxP & CSV

Underestimating documentation effort, lack of early QA involvement, and failing to define clear system boundaries.

Click to Flip Back

Global SAP GxP & CSV

What is an Installation Qualification (IQ)?

Click to Reveal

Global SAP GxP & CSV

Evidence that the SAP software and hardware infrastructure are installed correctly according to specifications.

Click to Flip Back

Global SAP GxP & CSV

What is an Operational Qualification (OQ)?

Click to Reveal

Global SAP GxP & CSV

Functional testing to verify that the SAP system operates as intended across all operational ranges.

Click to Flip Back

Global SAP GxP & CSV

What is a Performance Qualification (PQ)?

Click to Reveal

Global SAP GxP & CSV

Testing the integrated SAP system under real-world conditions to ensure it consistently meets performance criteria.

Click to Flip Back

Global SAP GxP & CSV

Why is 'Electronic Signature' (21 CFR Part 11) critical in SAP CSV?

Click to Reveal

Global SAP GxP & CSV

It ensures that digital approvals in SAP are as legally binding and traceable as handwritten signatures.

Click to Flip Back

Global SAP GxP & CSV

What is the purpose of a Traceability Matrix (TM)?

Click to Reveal

Global SAP GxP & CSV

To link each requirement (URS) to its functional design (FS), technical build, and final test case (OQ/PQ) for audit readiness.

Click to Flip Back

Global SAP GxP & CSV

How does 'Data Integrity' apply to SAP CSV?

Click to Reveal

Global SAP GxP & CSV

It follows the ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate) to ensure data is trustworthy throughout its lifecycle.

Click to Flip Back

Global SAP GxP & CSV

What is a 'Validation Summary Report' (VSR)?

Click to Reveal

Global SAP GxP & CSV

The final document that summarizes the validation activities and confirms the system is 'Live' and compliant.

Click to Flip Back

Global SAP GxP & CSV

What is the 'intended use' principle?

Click to Reveal

Global SAP GxP & CSV

The core of CSV; validation is not about the software's features, but whether it works for the specific business process it was designed for.

Click to Flip Back

Global SAP GxP & CSV

How does Change Management intersect with CSV?

Click to Reveal

Global SAP GxP & CSV

Any post-go-live change to a validated SAP system must undergo a formal impact assessment and re-validation if GxP-relevant.

Click to Flip Back

Global SAP GxP & CSV

What is Category 4 vs Category 5 in GAMP 5?

Click to Reveal

Global SAP GxP & CSV

Category 4 is configured software (standard SAP), while Category 5 is custom-coded software (ABAP developments).

Click to Flip Back

Global SAP GxP & CSV

What is a Functional Risk Assessment (FRA)?

Click to Reveal

Global SAP GxP & CSV

A step to identify which specific SAP functions carry high risk to patient safety or product quality.

Click to Flip Back

Global SAP GxP & CSV

Who is responsible for the final 'release' of a validated system?

Click to Reveal

Global SAP GxP & CSV

The Quality Unit (QA) and the System Owner.

Click to Flip Back

Global SAP GxP & CSV

What are peripheral systems in SAP CSV?

Click to Reveal

Global SAP GxP & CSV

External systems (LIMS, MES, WMS) that exchange GxP data with SAP and require interface validation.

Click to Flip Back

Global SAP GxP & CSV

Define 'Legacy System Migration' in CSV.

Click to Reveal

Global SAP GxP & CSV

The process of moving GxP data from an old system to SAP while maintaining data integrity and audit trails.

Click to Flip Back

Global SAP GxP & CSV

What is 'Retrospective Validation'?

Click to Reveal

Global SAP GxP & CSV

Validating an existing system that is already in use but lacks full documentation (rarely recommended today).

Click to Flip Back

Global SAP GxP & CSV

What is a Validation Plan (VP)?

Click to Reveal

Global SAP GxP & CSV

The roadmap defining the scope, responsibilities, and acceptance criteria for the entire SAP validation project.

Click to Flip Back

Global SAP GxP & CSV

What is a 'Critical Process Parameter' (CPP)?

Click to Reveal

Global SAP GxP & CSV

A parameter in SAP (like a temperature setpoint) that must be monitored and validated as it impacts product quality.

Click to Flip Back

Global SAP GxP & CSV

What is 'Vendor Audit' in the context of CSV?

Click to Reveal

Global SAP GxP & CSV

Assessing SAP or a hosting provider to ensure their software development and quality management systems are GxP-compliant.

Click to Flip Back

Global SAP GxP & CSV

What is 'Audit Trail Review'?

Click to Reveal

Global SAP GxP & CSV

A periodic check of SAP logs to ensure users are not bypassing GxP controls.

Click to Flip Back

China Compliance in GxP & CSV

What is MLPS 2.0 and its relevance to SAP in China?

Click to Reveal

China Compliance in GxP & CSV

The Multi-Level Protection Scheme; SAP systems in China must be graded and certified (usually Level 3) for cybersecurity.

Click to Flip Back

China Compliance in GxP & CSV

How does PIPL affect SAP user data?

Click to Reveal

China Compliance in GxP & CSV

Personal Information Protection Law; requires explicit consent and strict controls for any PII stored in or transferred from SAP China.

Click to Flip Back

China Compliance in GxP & CSV

What is the 'Golden Tax' integration requirement?

Click to Reveal

China Compliance in GxP & CSV

SAP China must integrate with the government's tax system for fapiao (invoice) issuance and validation.

Click to Flip Back

China Compliance in GxP & CSV

What is the NMPA's stance on SAP CSV?

Click to Reveal

China Compliance in GxP & CSV

The National Medical Products Administration (China's FDA) requires strict CSV for any SAP system used in drug or device manufacturing.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Data Localization' for SAP China?

Click to Reveal

China Compliance in GxP & CSV

Critical business and personal data generated in China must be stored on servers physically located within China.

Click to Flip Back

China Compliance in GxP & CSV

Define 'Cross-Border Data Transfer' (CBDT) in SAP.

Click to Reveal

China Compliance in GxP & CSV

The legal process of moving data from SAP China to a global HQ, requiring a security assessment by the CAC.

Click to Flip Back

China Compliance in GxP & CSV

What is the CAC?

Click to Reveal

China Compliance in GxP & CSV

Cyberspace Administration of China; the primary regulator for data security and PIPL compliance.

Click to Flip Back

China Compliance in GxP & CSV

How does the 'Data Security Law' (DSL) impact SAP projects?

Click to Reveal

China Compliance in GxP & CSV

It categorizes data and mandates protections based on the impact on national security.

Click to Flip Back

China Compliance in GxP & CSV

What is 'MLPS Filing'?

Click to Reveal

China Compliance in GxP & CSV

The formal process of submitting SAP system security designs to the local Public Security Bureau for approval.

Click to Flip Back

China Compliance in GxP & CSV

What is an 'Appointed Third-Party' audit in China CSV?

Click to Reveal

China Compliance in GxP & CSV

Engaging a China-certified agency to audit the SAP system’s cybersecurity (MLPS) compliance.

Click to Flip Back

China Compliance in GxP & CSV

Does SAP China require a 'GB' (Guobiao) standard check?

Click to Reveal

China Compliance in GxP & CSV

Yes, technical validation often includes checking against specific 'GB' national standards for encryption and security.

Click to Flip Back

China Compliance in GxP & CSV

How are 'Fapiao' audits conducted in a validated SAP environment?

Click to Reveal

China Compliance in GxP & CSV

Validation must prove that the SAP-to-Golden-Tax interface is accurate and tamper-proof.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Sensitive Personal Information' under PIPL?

Click to Reveal

China Compliance in GxP & CSV

Biometric data, medical history, or financial info in SAP that requires even higher levels of protection and consent.

Click to Flip Back

China Compliance in GxP & CSV

What is 'De-identification' in SAP China reporting?

Click to Reveal

China Compliance in GxP & CSV

Removing PII from SAP data before sending it to global dashboards to comply with localization laws.

Click to Flip Back

China Compliance in GxP & CSV

What is the 'Cryptographic Law' of China?

Click to Reveal

China Compliance in GxP & CSV

Requires that SAP systems use government-approved encryption algorithms for data storage and transmission.

Click to Flip Back

China Compliance in GxP & CSV

What is a 'Data Protection Impact Assessment' (DPIA)?

Click to Reveal

China Compliance in GxP & CSV

A mandatory PIPL step to assess risks before processing sensitive data in SAP.

Click to Flip Back

China Compliance in GxP & CSV

How does 'NMPA Annex 1' apply to SAP?

Click to Reveal

China Compliance in GxP & CSV

It provides specific guidelines for computerized systems used in pharmaceutical manufacturing.

Click to Flip Back

China Compliance in GxP & CSV

What is the 'Cybersecurity Review' for SAP PCE in China?

Click to Reveal

China Compliance in GxP & CSV

A review required if an SAP project involves purchasing critical network products that could affect national security.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Localization Validation'?

Click to Reveal

China Compliance in GxP & CSV

Validating the specific SAP China Add-on or local patches that are not part of the global core.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Joint and Several Liability' in PIPL?

Click to Reveal

China Compliance in GxP & CSV

Both the customer and SAP (if it is a service provider) can be held liable for data breaches in the cloud.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Self-Assessment' for data export?

Click to Reveal

China Compliance in GxP & CSV

The internal review a company must do before asking the government for permission to export SAP data.

Click to Flip Back

China Compliance in GxP & CSV

How is 'Audit Trail' compliance checked by NMPA?

Click to Reveal

China Compliance in GxP & CSV

Inspectors look for un-editable logs of every data entry, modification, and deletion in SAP.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Network Security Domain' in MLPS?

Click to Reveal

China Compliance in GxP & CSV

Structuring the SAP network into zones (Production, DMZ) with validated firewalls between them.

Click to Flip Back

China Compliance in GxP & CSV

What is the 'Designated Data Handler'?

Click to Reveal

China Compliance in GxP & CSV

The specific entity in China legally responsible for the SAP data under PIPL.

Click to Flip Back

China Compliance in GxP & CSV

What is 'Standard Contractual Clauses' (SCC) in China?

Click to Reveal

China Compliance in GxP & CSV

The legal templates provided by the CAC for transferring SAP data out of China.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How does CSV change for S/4HANA PCE compared to On-Premise?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Responsibility shifts from infrastructure management to vendor assessment and managed service oversight.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the impact of SAP's 2-year release cycle on PCE validation?

Click to Reveal

SAP S/4HANA Cloud (PCE)

It requires a 'Continuous Validation' strategy to handle frequent updates without disrupting GxP status.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the 'Shared Responsibility Model' in PCE CSV?

Click to Reveal

SAP S/4HANA Cloud (PCE)

SAP manages the cloud infrastructure (Qualified), while the customer manages the application and data (Validated).

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How does 'Automated Regression Testing' support PCE CSV?

Click to Reveal

SAP S/4HANA Cloud (PCE)

It allows for rapid verification of GxP processes whenever SAP applies patches or upgrades.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is a 'Validation Platform' in the PCE model?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Using tools like SAP Cloud ALM to manage validation documents and testing in a digital, integrated environment.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the customer's role in PCE Infrastructure Qualification?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Reviewing and approving the SOC 1/SOC 2 reports and SAP's own internal validation evidence.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

Does PCE allow for ABAP customization in CSV projects?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Yes, but custom code (GAMP Cat 5) requires significantly more validation effort than standard configuration.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How are SAP PCE 'Managed Services' validated?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Through a Service Level Agreement (SLA) and a clear definition of the vendor’s GxP-relevant operational procedures.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'Cloud Compliance' documentation for PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Standard packages provided by SAP to help customers accelerate their validation effort for the PCE environment.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the risk of 'Force-Upgrades' in PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Upgrades are mandatory within a certain window; validation must be planned and executed within that fixed timeframe.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How does BTP (Business Technology Platform) impact PCE validation?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Extensions on BTP are 'outside' the core SAP; their integration and data flow must be separately validated.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'Configuration as Code' in cloud CSV?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Treating SAP configurations as auditable data points that can be moved across environments via controlled transports.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

Why is 'Identity Management' (IAM) more critical in PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Because the system is accessed over the internet, requiring validated controls for multi-factor authentication and user provisioning.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the role of the 'Qualified Infrastructure' in PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

It is the foundation (provided by SAP) upon which the customer's validated SAP application sits.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

Does SAP PCE use the V-Model?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Yes, but it is often adapted into an 'Agile' V-Model to fit the cloud delivery speed.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'OQ by SAP'?

Click to Reveal

SAP S/4HANA Cloud (PCE)

SAP performs basic functional testing of the standard software, but the customer still must validate their specific configuration.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How does 'Sandbox' environment use differ in PCE CSV?

Click to Reveal

SAP S/4HANA Cloud (PCE)

It is used for the 'Risk Assessment' phase to see how standard SAP features handle GxP requirements before formal build.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is a 'Validation Assessment' for PCE notes?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Evaluating every SAP Note or Hotfix to see if it touches a GxP-critical part of the system.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is the 'One-System' fallacy in cloud?

Click to Reveal

SAP S/4HANA Cloud (PCE)

The mistake of thinking cloud validation is just 'signing off' what the vendor gives you; business processes remain the customer's responsibility.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'Electronic Document Management' (EDMS) for PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

A validated tool to house all cloud validation evidence (VP, URS, TM, VSR).

Click to Flip Back

SAP S/4HANA Cloud (PCE)

How are cloud 'Integrations' (e.g., via APIs) validated?

Click to Reveal

SAP S/4HANA Cloud (PCE)

By testing the data integrity and security of the connection point between PCE and other systems.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'SaaS validation' vs 'PCE validation'?

Click to Reveal

SAP S/4HANA Cloud (PCE)

PCE offers more control than SaaS, allowing for more detailed custom validation.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'Release Management' in a validated PCE setup?

Click to Reveal

SAP S/4HANA Cloud (PCE)

The controlled process of moving validated configurations from Dev to Test to Production.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'Tenant Separation' in PCE CSV?

Click to Reveal

SAP S/4HANA Cloud (PCE)

Verifying that the customer's GxP data is logically isolated from other customers in the SAP cloud.

Click to Flip Back

SAP S/4HANA Cloud (PCE)

What is 'User Acceptance Testing' (UAT) in PCE?

Click to Reveal

SAP S/4HANA Cloud (PCE)

The final stage where business users confirm the cloud system supports their GxP processes in the real world.

Click to Flip Back

Architecture & Toolset

Which SAP modules typically fall under GMP (Manufacturing)?

Click to Reveal

Architecture & Toolset

PP/PP-PI, QM, MM, EWM/WM, Batch Management, and ATTP (Serialization).

Click to Flip Back

Architecture & Toolset

Which SAP modules are primarily governed by GDP (Distribution)?

Click to Reveal

Architecture & Toolset

SD (Sales and Distribution), LE-TRA (Transportation), and Serialization components.

Click to Flip Back

Architecture & Toolset

How does GLP (Laboratory) manifest in SAP?

Click to Reveal

Architecture & Toolset

Through integration between the QM module and external LIMS (Lab Systems).

Click to Flip Back

Architecture & Toolset

What is the regulatory status of EU Annex 11 vs FDA Part 11?

Click to Reveal

Architecture & Toolset

Part 11 is binding US law; Annex 11 is EU guidance (though enforced as a standard).

Click to Flip Back

Architecture & Toolset

What is a GAMP Category 3 system?

Click to Reveal

Architecture & Toolset

Non-configured products (COTS) used 'as is' without business-specific configuration.

Click to Flip Back

Architecture & Toolset

What is the focus of 'Interface Validation'?

Click to Reveal

Architecture & Toolset

Proving data integrity and mapping accuracy during hand-offs between systems.

Click to Flip Back

Architecture & Toolset

How does Cloud ALM centralize validation deliverables?

Click to Reveal

Architecture & Toolset

It links URS, Functional Specs, Test Cases, and the RTM in one digital environment.

Click to Flip Back

Architecture & Toolset

Define the 'Federated Validation' pattern.

Click to Reveal

Architecture & Toolset

Maintaining a global validation backbone while adding local annexes for specific regions.

Click to Flip Back

Architecture & Toolset

Name two leading 'Paperless Validation' platforms.

Click to Reveal

Architecture & Toolset

Kneat Gx and ValGenesis VLMS.

Click to Flip Back

Architecture & Toolset

What tool identifies affected GxP objects during a patch?

Click to Reveal

Architecture & Toolset

LiveCompare or Panaya (Change-Impact Analysis tools).

Click to Flip Back

Architecture & Toolset

Define the 'Bluefield' migration path.

Click to Reveal

Architecture & Toolset

A selective data transition moving chosen processes to S/4HANA, balancing Greenfield and Brownfield.

Click to Flip Back

Architecture & Toolset

What is the 'Clean Core' benefit for CSV?

Click to Reveal

Architecture & Toolset

Reduces Cat 5 custom code footprint, simplifying the validation of future upgrades.

Click to Flip Back

Architecture & Toolset

What does 'Enduring' mean in ALCOA+?

Click to Reveal

Architecture & Toolset

Ensuring records are readable and exist for the entire required retention period.

Click to Flip Back

Architecture & Toolset

What is the NMPA Annex scope for computerized systems?

Click to Reveal

Architecture & Toolset

Broad scope: R&D, Clinical Trials, Manufacturing, and Post-Market.

Click to Flip Back

Architecture & Toolset

What is the 'GTI' validation requirement?

Click to Reveal

Architecture & Toolset

Proving accurate export of billing data to the state tax system for legal compliance.

Click to Flip Back

Architecture & Toolset

What is required for MLPS Level 3 certification?

Click to Reveal

Architecture & Toolset

Self-assessment plus mandatory annual audits by a certified third-party agency.

Click to Flip Back

Architecture & Toolset

How does expert expertise apply in CSA 'Unscripted Testing'?

Click to Reveal

Architecture & Toolset

Testers explore the system to find bugs rather than following a rigid pass/fail script.

Click to Flip Back

Architecture & Toolset

What are 'Delta Requirements'?

Click to Reveal

Architecture & Toolset

Business needs not met by SAP Best Practice, requiring custom configuration/code.

Click to Flip Back

Architecture & Toolset

What does the PCE 'QRS' grant the customer?

Click to Reveal

Architecture & Toolset

Legal audit rights over SAP's cloud infrastructure and QMS documentation.

Click to Flip Back

Architecture & Toolset

What is 'Continuous Validation'?

Click to Reveal

Architecture & Toolset

Using automated regression to keep the system validated through cloud updates.

Click to Flip Back

Architecture & Toolset

Why is 'Traceability' the heart of CSV?

Click to Reveal

Architecture & Toolset

It proves every regulatory requirement was designed, built, and successfully tested.

Click to Flip Back

Architecture & Toolset

What is the role of the 'Process Owner'?

Click to Reveal

Architecture & Toolset

The individual responsible for the business process and its 'Intended Use' compliance.

Click to Flip Back

Architecture & Toolset

How does China's DSL classify data?

Click to Reveal

Architecture & Toolset

Categorizes data based on national security impact to determine protection levels.

Click to Flip Back

Architecture & Toolset

What is 'Data Residency' under PIPL?

Click to Reveal

Architecture & Toolset

Storing personal and important data on servers physically located inside China.

Click to Flip Back

Architecture & Toolset

What is the 'V-Model'?

Click to Reveal

Architecture & Toolset

Lifecycle model mapping requirement phases (URS/FS) to testing phases (PQ/OQ).

Click to Flip Back