100 knowledge cards across 4 compliance domains
Global SAP GxP & CSV · China Compliance in GxP & CSV · SAP S/4HANA Cloud (PCE) · Architecture & Toolset
Prepared by Mark & Xincheng · April 2026
Project Wiki for Regulatory Compliance prepared by Mark & Xincheng, April 2026
What is the primary goal of Computer System Validation (CSV) in SAP projects?
Click to Reveal
To provide documented evidence that the SAP system consistently performs according to its intended use and meets GxP regulatory requirements.
Click to Flip Back
Explain the relationship between CSV and GxP.
Click to Reveal
CSV is the process used to ensure that computerized systems (like SAP) comply with GxP (Good Practice) regulations, such as GMP, GDP, and GCP.
Click to Flip Back
What is the 'V-Model' in the context of SAP CSV?
Click to Reveal
A SDLC framework that maps requirements (User Requirements, Functional Specs) directly to their corresponding testing phases (IQ, OQ, PQ).
Click to Flip Back
What does GAMP 5 stand for, and why is it important?
Click to Reveal
Good Automated Manufacturing Practice (Version 5); it is the industry-standard risk-based approach for compliant GxP computerized systems.
Click to Flip Back
How does CSV impact the SAP Blueprinting phase?
Click to Reveal
It requires the early definition of User Requirements (URS) and a Risk Assessment to determine which SAP processes are GxP-relevant.
Click to Flip Back
What are the common pitfalls in SAP CSV projects?
Click to Reveal
Underestimating documentation effort, lack of early QA involvement, and failing to define clear system boundaries.
Click to Flip Back
What is an Installation Qualification (IQ)?
Click to Reveal
Evidence that the SAP software and hardware infrastructure are installed correctly according to specifications.
Click to Flip Back
What is an Operational Qualification (OQ)?
Click to Reveal
Functional testing to verify that the SAP system operates as intended across all operational ranges.
Click to Flip Back
What is a Performance Qualification (PQ)?
Click to Reveal
Testing the integrated SAP system under real-world conditions to ensure it consistently meets performance criteria.
Click to Flip Back
Why is 'Electronic Signature' (21 CFR Part 11) critical in SAP CSV?
Click to Reveal
It ensures that digital approvals in SAP are as legally binding and traceable as handwritten signatures.
Click to Flip Back
What is the purpose of a Traceability Matrix (TM)?
Click to Reveal
To link each requirement (URS) to its functional design (FS), technical build, and final test case (OQ/PQ) for audit readiness.
Click to Flip Back
How does 'Data Integrity' apply to SAP CSV?
Click to Reveal
It follows the ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate) to ensure data is trustworthy throughout its lifecycle.
Click to Flip Back
What is a 'Validation Summary Report' (VSR)?
Click to Reveal
The final document that summarizes the validation activities and confirms the system is 'Live' and compliant.
Click to Flip Back
What is the 'intended use' principle?
Click to Reveal
The core of CSV; validation is not about the software's features, but whether it works for the specific business process it was designed for.
Click to Flip Back
How does Change Management intersect with CSV?
Click to Reveal
Any post-go-live change to a validated SAP system must undergo a formal impact assessment and re-validation if GxP-relevant.
Click to Flip Back
What is Category 4 vs Category 5 in GAMP 5?
Click to Reveal
Category 4 is configured software (standard SAP), while Category 5 is custom-coded software (ABAP developments).
Click to Flip Back
What is a Functional Risk Assessment (FRA)?
Click to Reveal
A step to identify which specific SAP functions carry high risk to patient safety or product quality.
Click to Flip Back
Who is responsible for the final 'release' of a validated system?
Click to Reveal
The Quality Unit (QA) and the System Owner.
Click to Flip Back
What are peripheral systems in SAP CSV?
Click to Reveal
External systems (LIMS, MES, WMS) that exchange GxP data with SAP and require interface validation.
Click to Flip Back
Define 'Legacy System Migration' in CSV.
Click to Reveal
The process of moving GxP data from an old system to SAP while maintaining data integrity and audit trails.
Click to Flip Back
What is 'Retrospective Validation'?
Click to Reveal
Validating an existing system that is already in use but lacks full documentation (rarely recommended today).
Click to Flip Back
What is a Validation Plan (VP)?
Click to Reveal
The roadmap defining the scope, responsibilities, and acceptance criteria for the entire SAP validation project.
Click to Flip Back
What is a 'Critical Process Parameter' (CPP)?
Click to Reveal
A parameter in SAP (like a temperature setpoint) that must be monitored and validated as it impacts product quality.
Click to Flip Back
What is 'Vendor Audit' in the context of CSV?
Click to Reveal
Assessing SAP or a hosting provider to ensure their software development and quality management systems are GxP-compliant.
Click to Flip Back
What is 'Audit Trail Review'?
Click to Reveal
A periodic check of SAP logs to ensure users are not bypassing GxP controls.
Click to Flip Back
What is MLPS 2.0 and its relevance to SAP in China?
Click to Reveal
The Multi-Level Protection Scheme; SAP systems in China must be graded and certified (usually Level 3) for cybersecurity.
Click to Flip Back
How does PIPL affect SAP user data?
Click to Reveal
Personal Information Protection Law; requires explicit consent and strict controls for any PII stored in or transferred from SAP China.
Click to Flip Back
What is the 'Golden Tax' integration requirement?
Click to Reveal
SAP China must integrate with the government's tax system for fapiao (invoice) issuance and validation.
Click to Flip Back
What is the NMPA's stance on SAP CSV?
Click to Reveal
The National Medical Products Administration (China's FDA) requires strict CSV for any SAP system used in drug or device manufacturing.
Click to Flip Back
What is 'Data Localization' for SAP China?
Click to Reveal
Critical business and personal data generated in China must be stored on servers physically located within China.
Click to Flip Back
Define 'Cross-Border Data Transfer' (CBDT) in SAP.
Click to Reveal
The legal process of moving data from SAP China to a global HQ, requiring a security assessment by the CAC.
Click to Flip Back
What is the CAC?
Click to Reveal
Cyberspace Administration of China; the primary regulator for data security and PIPL compliance.
Click to Flip Back
How does the 'Data Security Law' (DSL) impact SAP projects?
Click to Reveal
It categorizes data and mandates protections based on the impact on national security.
Click to Flip Back
What is 'MLPS Filing'?
Click to Reveal
The formal process of submitting SAP system security designs to the local Public Security Bureau for approval.
Click to Flip Back
What is an 'Appointed Third-Party' audit in China CSV?
Click to Reveal
Engaging a China-certified agency to audit the SAP system’s cybersecurity (MLPS) compliance.
Click to Flip Back
Does SAP China require a 'GB' (Guobiao) standard check?
Click to Reveal
Yes, technical validation often includes checking against specific 'GB' national standards for encryption and security.
Click to Flip Back
How are 'Fapiao' audits conducted in a validated SAP environment?
Click to Reveal
Validation must prove that the SAP-to-Golden-Tax interface is accurate and tamper-proof.
Click to Flip Back
What is 'Sensitive Personal Information' under PIPL?
Click to Reveal
Biometric data, medical history, or financial info in SAP that requires even higher levels of protection and consent.
Click to Flip Back
What is 'De-identification' in SAP China reporting?
Click to Reveal
Removing PII from SAP data before sending it to global dashboards to comply with localization laws.
Click to Flip Back
What is the 'Cryptographic Law' of China?
Click to Reveal
Requires that SAP systems use government-approved encryption algorithms for data storage and transmission.
Click to Flip Back
What is a 'Data Protection Impact Assessment' (DPIA)?
Click to Reveal
A mandatory PIPL step to assess risks before processing sensitive data in SAP.
Click to Flip Back
How does 'NMPA Annex 1' apply to SAP?
Click to Reveal
It provides specific guidelines for computerized systems used in pharmaceutical manufacturing.
Click to Flip Back
What is the 'Cybersecurity Review' for SAP PCE in China?
Click to Reveal
A review required if an SAP project involves purchasing critical network products that could affect national security.
Click to Flip Back
What is 'Localization Validation'?
Click to Reveal
Validating the specific SAP China Add-on or local patches that are not part of the global core.
Click to Flip Back
What is 'Joint and Several Liability' in PIPL?
Click to Reveal
Both the customer and SAP (if it is a service provider) can be held liable for data breaches in the cloud.
Click to Flip Back
What is 'Self-Assessment' for data export?
Click to Reveal
The internal review a company must do before asking the government for permission to export SAP data.
Click to Flip Back
How is 'Audit Trail' compliance checked by NMPA?
Click to Reveal
Inspectors look for un-editable logs of every data entry, modification, and deletion in SAP.
Click to Flip Back
What is 'Network Security Domain' in MLPS?
Click to Reveal
Structuring the SAP network into zones (Production, DMZ) with validated firewalls between them.
Click to Flip Back
What is the 'Designated Data Handler'?
Click to Reveal
The specific entity in China legally responsible for the SAP data under PIPL.
Click to Flip Back
What is 'Standard Contractual Clauses' (SCC) in China?
Click to Reveal
The legal templates provided by the CAC for transferring SAP data out of China.
Click to Flip Back
How does CSV change for S/4HANA PCE compared to On-Premise?
Click to Reveal
Responsibility shifts from infrastructure management to vendor assessment and managed service oversight.
Click to Flip Back
What is the impact of SAP's 2-year release cycle on PCE validation?
Click to Reveal
It requires a 'Continuous Validation' strategy to handle frequent updates without disrupting GxP status.
Click to Flip Back
What is the 'Shared Responsibility Model' in PCE CSV?
Click to Reveal
SAP manages the cloud infrastructure (Qualified), while the customer manages the application and data (Validated).
Click to Flip Back
How does 'Automated Regression Testing' support PCE CSV?
Click to Reveal
It allows for rapid verification of GxP processes whenever SAP applies patches or upgrades.
Click to Flip Back
What is a 'Validation Platform' in the PCE model?
Click to Reveal
Using tools like SAP Cloud ALM to manage validation documents and testing in a digital, integrated environment.
Click to Flip Back
What is the customer's role in PCE Infrastructure Qualification?
Click to Reveal
Reviewing and approving the SOC 1/SOC 2 reports and SAP's own internal validation evidence.
Click to Flip Back
Does PCE allow for ABAP customization in CSV projects?
Click to Reveal
Yes, but custom code (GAMP Cat 5) requires significantly more validation effort than standard configuration.
Click to Flip Back
How are SAP PCE 'Managed Services' validated?
Click to Reveal
Through a Service Level Agreement (SLA) and a clear definition of the vendor’s GxP-relevant operational procedures.
Click to Flip Back
What is 'Cloud Compliance' documentation for PCE?
Click to Reveal
Standard packages provided by SAP to help customers accelerate their validation effort for the PCE environment.
Click to Flip Back
What is the risk of 'Force-Upgrades' in PCE?
Click to Reveal
Upgrades are mandatory within a certain window; validation must be planned and executed within that fixed timeframe.
Click to Flip Back
How does BTP (Business Technology Platform) impact PCE validation?
Click to Reveal
Extensions on BTP are 'outside' the core SAP; their integration and data flow must be separately validated.
Click to Flip Back
What is 'Configuration as Code' in cloud CSV?
Click to Reveal
Treating SAP configurations as auditable data points that can be moved across environments via controlled transports.
Click to Flip Back
Why is 'Identity Management' (IAM) more critical in PCE?
Click to Reveal
Because the system is accessed over the internet, requiring validated controls for multi-factor authentication and user provisioning.
Click to Flip Back
What is the role of the 'Qualified Infrastructure' in PCE?
Click to Reveal
It is the foundation (provided by SAP) upon which the customer's validated SAP application sits.
Click to Flip Back
Does SAP PCE use the V-Model?
Click to Reveal
Yes, but it is often adapted into an 'Agile' V-Model to fit the cloud delivery speed.
Click to Flip Back
What is 'OQ by SAP'?
Click to Reveal
SAP performs basic functional testing of the standard software, but the customer still must validate their specific configuration.
Click to Flip Back
How does 'Sandbox' environment use differ in PCE CSV?
Click to Reveal
It is used for the 'Risk Assessment' phase to see how standard SAP features handle GxP requirements before formal build.
Click to Flip Back
What is a 'Validation Assessment' for PCE notes?
Click to Reveal
Evaluating every SAP Note or Hotfix to see if it touches a GxP-critical part of the system.
Click to Flip Back
What is the 'One-System' fallacy in cloud?
Click to Reveal
The mistake of thinking cloud validation is just 'signing off' what the vendor gives you; business processes remain the customer's responsibility.
Click to Flip Back
What is 'Electronic Document Management' (EDMS) for PCE?
Click to Reveal
A validated tool to house all cloud validation evidence (VP, URS, TM, VSR).
Click to Flip Back
How are cloud 'Integrations' (e.g., via APIs) validated?
Click to Reveal
By testing the data integrity and security of the connection point between PCE and other systems.
Click to Flip Back
What is 'SaaS validation' vs 'PCE validation'?
Click to Reveal
PCE offers more control than SaaS, allowing for more detailed custom validation.
Click to Flip Back
What is 'Release Management' in a validated PCE setup?
Click to Reveal
The controlled process of moving validated configurations from Dev to Test to Production.
Click to Flip Back
What is 'Tenant Separation' in PCE CSV?
Click to Reveal
Verifying that the customer's GxP data is logically isolated from other customers in the SAP cloud.
Click to Flip Back
What is 'User Acceptance Testing' (UAT) in PCE?
Click to Reveal
The final stage where business users confirm the cloud system supports their GxP processes in the real world.
Click to Flip Back
Which SAP modules typically fall under GMP (Manufacturing)?
Click to Reveal
PP/PP-PI, QM, MM, EWM/WM, Batch Management, and ATTP (Serialization).
Click to Flip Back
Which SAP modules are primarily governed by GDP (Distribution)?
Click to Reveal
SD (Sales and Distribution), LE-TRA (Transportation), and Serialization components.
Click to Flip Back
How does GLP (Laboratory) manifest in SAP?
Click to Reveal
Through integration between the QM module and external LIMS (Lab Systems).
Click to Flip Back
What is the regulatory status of EU Annex 11 vs FDA Part 11?
Click to Reveal
Part 11 is binding US law; Annex 11 is EU guidance (though enforced as a standard).
Click to Flip Back
What is a GAMP Category 3 system?
Click to Reveal
Non-configured products (COTS) used 'as is' without business-specific configuration.
Click to Flip Back
What is the focus of 'Interface Validation'?
Click to Reveal
Proving data integrity and mapping accuracy during hand-offs between systems.
Click to Flip Back
How does Cloud ALM centralize validation deliverables?
Click to Reveal
It links URS, Functional Specs, Test Cases, and the RTM in one digital environment.
Click to Flip Back
Define the 'Federated Validation' pattern.
Click to Reveal
Maintaining a global validation backbone while adding local annexes for specific regions.
Click to Flip Back
Name two leading 'Paperless Validation' platforms.
Click to Reveal
Kneat Gx and ValGenesis VLMS.
Click to Flip Back
What tool identifies affected GxP objects during a patch?
Click to Reveal
LiveCompare or Panaya (Change-Impact Analysis tools).
Click to Flip Back
Define the 'Bluefield' migration path.
Click to Reveal
A selective data transition moving chosen processes to S/4HANA, balancing Greenfield and Brownfield.
Click to Flip Back
What is the 'Clean Core' benefit for CSV?
Click to Reveal
Reduces Cat 5 custom code footprint, simplifying the validation of future upgrades.
Click to Flip Back
What does 'Enduring' mean in ALCOA+?
Click to Reveal
Ensuring records are readable and exist for the entire required retention period.
Click to Flip Back
What is the NMPA Annex scope for computerized systems?
Click to Reveal
Broad scope: R&D, Clinical Trials, Manufacturing, and Post-Market.
Click to Flip Back
What is the 'GTI' validation requirement?
Click to Reveal
Proving accurate export of billing data to the state tax system for legal compliance.
Click to Flip Back
What is required for MLPS Level 3 certification?
Click to Reveal
Self-assessment plus mandatory annual audits by a certified third-party agency.
Click to Flip Back
How does expert expertise apply in CSA 'Unscripted Testing'?
Click to Reveal
Testers explore the system to find bugs rather than following a rigid pass/fail script.
Click to Flip Back
What are 'Delta Requirements'?
Click to Reveal
Business needs not met by SAP Best Practice, requiring custom configuration/code.
Click to Flip Back
What does the PCE 'QRS' grant the customer?
Click to Reveal
Legal audit rights over SAP's cloud infrastructure and QMS documentation.
Click to Flip Back
What is 'Continuous Validation'?
Click to Reveal
Using automated regression to keep the system validated through cloud updates.
Click to Flip Back
Why is 'Traceability' the heart of CSV?
Click to Reveal
It proves every regulatory requirement was designed, built, and successfully tested.
Click to Flip Back
What is the role of the 'Process Owner'?
Click to Reveal
The individual responsible for the business process and its 'Intended Use' compliance.
Click to Flip Back
How does China's DSL classify data?
Click to Reveal
Categorizes data based on national security impact to determine protection levels.
Click to Flip Back
What is 'Data Residency' under PIPL?
Click to Reveal
Storing personal and important data on servers physically located inside China.
Click to Flip Back
What is the 'V-Model'?
Click to Reveal
Lifecycle model mapping requirement phases (URS/FS) to testing phases (PQ/OQ).
Click to Flip Back