What are examples of CSA risk-based testing for high, medium, and low risk?
High-risk examples — batch release calculations, e-signature enforcement, critical alarm logic — get scripted testing with pre-defined steps and expected results. Medium-risk examples — deviation routing, reviewed reports, training reminders — get scenario-based testing, recorded but not scripted line by line. Low-risk examples — cosmetic UI, unconfigured vendor features, non-GxP tools — get light scenario testing or a record review.
The hard part of CSA was never the concept. It's knowing which testing method actually applies to the feature sitting in front of you. Here it is, tier by tier, with real GxP system examples.
How Risk Level Is Determined
Two questions set the tier for any software feature: does it directly affect patient safety, product quality, or data integrity, and is there an independent way to catch a failure before it causes harm? Yes to the first with no independent check is high risk. A supporting role with a human review or downstream check before consequence is medium risk. No meaningful GxP impact at all is low risk — regardless of how central the feature feels to daily use.
High-Risk Testing Examples
High-risk features get scripted testing — pre-defined steps, inputs, and expected results, with edge cases built around specification limits, executed under a formal, traceable protocol.
| Feature / System | Why It's High Risk | What the Evidence Looks Like |
|---|---|---|
| Batch release calculation logic (MES/ERP) | Directly determines product disposition; an error could release an out-of-spec batch | Scripted test cases at, above, and below spec limits, with pass/fail recorded against each |
| Electronic signature enforcement (LIMS/QMS) | Controls approval of GxP records; a bypass would break accountability entirely | Scripted verification that signing is enforced at every required step, with no workaround path |
| Potency/assay calculation (chromatography data system) | Feeds directly into a release decision with no independent recheck before use | Scripted testing across a range of inputs, including known edge-case values near acceptance limits |
| Alarm logic on environmental monitoring (sterile manufacturing) | A missed excursion alarm could allow contaminated product to proceed undetected | Scripted testing of trigger thresholds and escalation routing for each alarm condition |
Medium-Risk Testing Examples
Medium-risk features get scenario-based testing — FDA's final September 2025 terminology, replacing the draft's "ad hoc testing." Testing stays purposeful and recorded, but without a rigid, line-by-line script.
| Feature / System | Why It's Medium Risk | What the Evidence Looks Like |
|---|---|---|
| Deviation/CAPA routing logic (QMS) | Supports the quality process, but a person reviews and approves before any consequence | A handful of representative deviation types run through, outcomes and screenshots recorded |
| Certificate of Analysis draft compilation (LIMS) | Output is reviewed and approved by a QA reviewer before it's used for anything | Exploratory testing across representative sample types, results documented |
| Training due-date reminder notifications (LMS) | Supports compliance tracking, but a missed reminder is caught by other periodic checks | Scenario testing of upcoming and overdue cases, confirmed and recorded |
| Equipment performance trending dashboard (MES) | Used for internal visibility, not a direct release or disposition decision | Scenario testing confirming data displays accurately for a few representative periods |
Low-Risk Testing Examples
Low-risk features can rely on light scenario testing or a record review, often leveraging the vendor's own test evidence directly rather than re-testing from scratch.
| Feature / System | Why It's Low Risk | What the Evidence Looks Like |
|---|---|---|
| Column sort order / field label display (any GxP system) | Cosmetic; no effect on data, decisions, or compliance | Brief visual confirmation, recorded in a line or two, or skipped with documented rationale |
| Standard PDF export button (unconfigured vendor feature) | Unmodified commercial functionality already covered by vendor testing | Vendor test evidence referenced directly; no independent re-testing needed |
| Non-GxP document search/filter tool | No GxP data or decision involved in what it searches | Light scenario check that search returns expected results |
| Routine system login confirmation notification | No regulatory content; purely a convenience notification | Record review confirming the notification fires; no dedicated test case required |
Terminology note: FDA's final CSA guidance (September 2025) replaced "ad hoc testing" with "scenario-based testing" specifically to make clear that unscripted testing still needs to be purposeful and directed at realistic use cases — not undirected, random poking at the software. The flexibility didn't change; the label changed to stop teams from treating it as an excuse to skip planning.
How GoVal Applies This
GoVal classifies each system by GAMP 5 category and risk tier at intake, then scales required test depth and documentation to that classification automatically — scripted protocols for high-risk functions, scenario-based testing for medium-risk ones, light evidence for low-risk functions — so the tiering above gets applied consistently across a portfolio instead of being re-judged, feature by feature, by whoever happens to be running that day's validation.
Related Topics
Frequently Asked Questions
What are examples of high-risk CSA testing? +
What are examples of medium-risk CSA testing? +
What are examples of low-risk CSA testing? +
How do you decide if a software feature is high, medium, or low risk under CSA? +
Is "ad hoc testing" still the correct term under FDA's final CSA guidance? +
Can vendor testing evidence replace testing for low-risk features? +
How does GoVal support risk-based test scoping under CSA? +
Apply risk-based test scoping consistently across your systems
GAMP 5 classification, scripted and scenario-based test workflows, and audit-trailed evidence — in GoVal.
