Create deviations at each configured classification tier (minor, major, critical). Confirm each routes to the correct workflow path, triggers the correct mandatory fields and investigation tasks, and that the classification value cannot be silently changed after the first approval without generating an explicit reclassification record.
Change the classification of a deviation before its first approval transition. Retrieve the audit trail and confirm the original classification value, new value, user, and timestamp are captured. If they are not, document this as an audit trail gap requiring either a configuration change or a procedural control to prevent pre-approval reclassification without evidence.
Attempt to close a major deviation with no linked CAPA. Confirm the system blocks closure. Attempt with a linked CAPA in Draft state — confirm still blocked. Complete the CAPA and confirm closure is now available. Document each system response explicitly.
Create deviations matching each configured reportability trigger condition (product type, deviation type, impact classification combination). Confirm the reportability flag or task fires. Then create a deviation deliberately not matching any trigger condition and confirm the flag does not fire — confirming both positive and negative cases of the logic.
Attempt to directly edit the investigation due date field on a deviation in progress. Confirm either the field is not directly editable and requires a formal extension request workflow, or that any edit generates an audit trail entry with the original date and an approving user. Document the specific mechanism used.
Close a deviation and confirm the e-signature prompt displays the configured meaning statement. Verify the meaning statement specifically describes the quality decision being made (not a generic approval statement). Confirm the signature event — user, timestamp, meaning text — is captured in the audit trail and is not editable after the fact.