Execute each GxP-significant lifecycle transition (initiation, approval, closure) with a user assigned to the authorised role. Confirm the transition completes, the e-signature prompt appears with the correct meaning statement, and the state change is captured in the audit trail with user ID and timestamp.
Attempt each GxP-significant transition with a user assigned to a role that should not have that permission. Confirm the transition action is either not visible or blocked when attempted. This test must be run for each role/transition combination in scope — it cannot be inferred from positive testing.
Attempt to close a CAPA record with no linked effectiveness check present. Confirm the system blocks closure. Then link an effectiveness check in 'Draft' state — confirm this is still insufficient. Complete and approve the effectiveness check and confirm closure is now available. Document the specific system response at each step.
Make a change to each GxP-relevant custom field on the CAPA record after initial save. Retrieve the audit trail and confirm every custom field change is captured with original value, new value, user, and timestamp — not just standard Vault fields. This test is specific to your field configuration, not derivable from Vault's default behaviour.
Attempt to initiate a CAPA without linking it to a source record (deviation, investigation) if your configuration requires this. Confirm the system blocks initiation. Link to a source record and confirm the source record's status reflects the open CAPA. Attempt to close the source deviation while the CAPA remains open and confirm this is blocked or requires documented justification.
Using an accelerated due date, allow a CAPA to become overdue. Confirm the initial notification fires to the correct recipient(s) with correct content (CAPA ID, due date, current state). If escalation tiers are configured (30-day, 60-day), test each tier separately — document the testing method for time-acceleration in the protocol, as auditors will ask how time-dependent notifications were validated without live production time.