Quality Management
Software Validation
Compliance Built Into the Systems Behind Your Imaging Endpoints
Clinical trial imaging is only as dependable as the systems that receive images, protect blinded reviews, record measurements and deliver endpoint data. Software validation establishes documented evidence that these systems consistently perform as intended. For sponsors, that means confidence not only in the imaging assessment, but also in the reliability and traceability of the electronic record supporting it.
GAMP 5 provides the internationally used good-practice framework for achieving that control across a computerized system’s lifecycle. FDA requirements establish the applicable obligations for regulated records and electronic signatures; FDA guidance explains the agency’s current recommendations for electronic systems in clinical investigations. Together, they connect intended use, risk-based testing, data integrity and continued control—not simply a test performed before a system goes live.
Intrinsic Imaging integrates GAMP 5 principles and validation activities designed to meet applicable FDA requirements into our imaging core lab quality framework. We connect system requirements to verification evidence, study-specific configuration and controlled change. The advantage for your trial is a validation approach grounded in the actual imaging workflow: protecting endpoint data, supporting sponsor qualification and making the evidence behind system reliability available for audit review.
What Is GAMP 5?
GAMP stands for Good Automated Manufacturing Practice. Published by the International Society for Pharmaceutical Engineering (ISPE), GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems is good-practice guidance for systems used in regulated life-science activities. GxP refers to the applicable good-practice disciplines, including Good Clinical Practice. Despite its manufacturing origins, the framework addresses computerized systems across regulated activities, including clinical trial workflows.
The Second Edition emphasizes critical thinking: understand what a system must do, identify where failure could harm participants or compromise data, and use proportionate evidence to demonstrate control. Validation therefore covers the configured system, its users, interfaces and operating procedures—not just the supplier’s software product. GAMP 5 is guidance, not a regulation or a certification.
Understand Intended Use
Define the imaging process, the regulated records and the functions that support it. Requirements provide the basis for acceptance criteria and verification.
Apply Risk-Based Verification
Focus testing on functions whose failure could affect participant protection, blinding or endpoint integrity. Scale the evidence to the system’s complexity and risk rather than treating every function identically.
Use Supplier Evidence Intelligently
Assess supplier capability and relevant documentation, then address the additional verification needed for the study’s configuration, interfaces and workflow. Supplier evidence supports validation; it does not eliminate responsibility for intended use.
Control the Entire Lifecycle
Maintain the validated state through approved release, trained users, change assessment, incident handling, periodic review and controlled record retention or retirement.
What Does FDA Require for Software Validation?
FDA’s requirements depend on the regulated activity and the records a system maintains. The underlying clinical investigation regulations—often called predicate rules—establish which records must be created and retained. When those required records are maintained electronically, or electronic signatures replace required handwritten signatures, 21 CFR Part 11 may apply.
For closed systems within its scope, Part 11 §11.10(a) requires validation to ensure accuracy, reliability, consistent intended performance and the ability to discern invalid or altered records. Other provisions address record copies and retention, authorized access, audit trails, operational checks, authority checks, training and documentation control. Open systems and electronic signatures have additional applicable controls.
FDA’s October 2024 clinical electronic-systems guidance recommends a risk-based approach to validation, considering intended use and the potential impact on participant protection and the reliability of trial results. FDA’s 2003 Part 11 guidance describes a narrower interpretation of scope and enforcement discretion for certain provisions; it does not remove the underlying clinical-record obligations. Our approach considers both the applicable regulations and the clinical guidance rather than treating every software system as subject to identical requirements.
Demonstrate Intended Performance
Establish requirements and acceptance criteria, challenge critical functions and retain evidence showing that the configured system produces reliable results—including under invalid-input and failure conditions.
Protect Records and Accountability
Control access, preserve accurate and complete records, and maintain applicable time-stamped audit trails without obscuring earlier information. Where electronic signatures are used, preserve identity, meaning and linkage to the signed record.
Keep the System Under Control
Use trained personnel, controlled procedures and documentation, and evaluate changes that could affect validated functions. Verification addresses the impact of a change before the revised system is released for use.
Make Evidence Available for Review
Retain validation documentation and protect clinical records for their applicable retention period. Support retrieval and accurate, complete copies so sponsors and inspectors can review the record and its relevant context.
The Intrinsic Imaging Advantage
Choosing an imaging CRO means choosing the systems and controls behind your study evidence. Intrinsic Imaging connects software validation with imaging expertise, three FDA inspections with zero Form 483 observations and five ISO certifications. These are complementary strengths: inspection history and certifications provide quality context, while intended-use validation addresses the reliability of the particular system and study workflow.
Confidence in Your Endpoint Data
Verification follows the imaging record from receipt through assessment and delivery. Checks on identifiers, measurements, review sequencing and transfers help address errors that could compromise the evidence supporting your trial.
A Clearer Basis for Sponsor Oversight
Requirements, risk decisions, traceability and release evidence give sponsors a structured basis for system qualification and audit discussions—not simply an assurance that a platform has been tested.
Control Beyond Study Start-Up
Study-specific configuration and change assessment keep validation connected to actual use. Security, privacy and continuity disciplines support reliable imaging operations throughout the study and record-retention lifecycle.
From Requirements to a Maintained Validated State
Validation is not a one-time test or a vendor checklist. Our approach connects each important requirement to its risk, verification evidence and operational controls. Documentation is proportionate to the system’s complexity and the consequences of failure.
- 01
Define Intended Use
Identify the imaging workflow, users, regulated records and interfaces. User requirements establish what the system must do, including study-specific configurations and acceptance criteria.
Intended-use statement · User requirements
- 02
Assess Risk and Suppliers
Evaluate how a failure could affect participant protection, blinding, image interpretation or endpoint integrity. Assess supplier evidence and focus verification on the functions that matter most.
Risk assessment · Supplier assessment
- 03
Verify the Configured System
Test the actual workflow and configuration, not just the software name. Challenge permissions, calculations, data transfers and failure handling, with test rigor proportional to risk.
Test evidence · Requirements traceability
- 04
Review and Release
Review results against acceptance criteria, assess deviations and document the release decision. Approved procedures and user training support controlled use in the study.
Validation summary · Release authorization
- 05
Maintain the Validated State
Assess changes before implementation and repeat relevant verification when risk warrants it. Periodic review, incident handling, backup recovery and controlled retirement protect the records throughout their lifecycle.
Change control · Review and retention records
Validation Where Imaging Data Are Most Vulnerable
We translate regulatory expectations into imaging-specific verification objectives. The scope reflects the system’s intended use and applicable records, including additional protections for open systems and electronic signatures when relevant.
| Control Area | Validation Focus | Verification Objective |
|---|---|---|
| Access and Blinding | Unique user identities, role-based permissions and separation of reader, adjudicator and administrative activities. | Challenge unauthorized access and study-specific visibility restrictions. |
| Image and Record Integrity | Preserve the relationship between participant identifiers, visits, images, assessments and released results. | Reconcile receipt, processing and export; test incomplete, duplicate or incorrectly mapped records. |
| Audit Trails | Secure, computer-generated, time-stamped histories for applicable record creation, modification and deletion, without obscuring prior information. | Verify attribution, chronology, reviewability and retention of relevant changes. |
| Electronic Signatures | Where used, link the signature to its record and preserve the signer’s name, date/time and meaning of the signature. | Test identity controls, signature manifestation and record linkage. |
| Measurements and Workflow | Defined measurement rules, review sequencing, adjudication logic and study-specific configuration. | Challenge expected results, boundary conditions, invalid inputs and workflow exceptions. |
| Interfaces and Data Delivery | Controlled mappings and transfers that preserve record content and meaning between systems. | Check completeness, units, precision, identifiers and handling of interrupted or failed transfers. |
| Recovery and Retention | Protected records, appropriate retention, recoverable backups and accurate, complete copies for review and inspection. | Exercise restoration, retrieval and export, including associated metadata and audit trails where applicable. |
Evidence That Supports Sponsor Oversight
A defensible validation package explains what was assessed, why the evidence is sufficient and how the system remains controlled. Sponsor discussions can address the relevant system scope, risk decisions and documentation needed for qualification and audit review.
- Defined requirements and configuration baseline
- Risk assessment and supplier evidence review
- Traceability between requirements and verification
- Test results, deviation assessment and release decision
- Change history, training and retention arrangements
System Reliability and Clinical Performance
The software operating a clinical trial workflow and the investigational imaging product answer different validation questions. A validated reading platform does not, by itself, establish an AI algorithm’s clinical performance or authorize a medical device.
Intrinsic Imaging also supports independent AI/CAD clinical validation studies and medical device imaging trials. These activities evaluate the product’s intended clinical task while controlled systems protect the evidence generated during the study.
Our FDA inspection history and five ISO certifications provide further context for our quality framework. Neither is a blanket FDA approval of software.
Software Validation Questions
Build Confidence Into Your Imaging Workflow
Discuss system qualification, study-specific controls and validation evidence with Intrinsic Imaging.
Regulatory and Good-Practice References
GAMP 5 and FDA guidance inform a risk-based approach; guidance is not itself a binding regulation. Applicable requirements depend on intended use, the regulated activity and the records maintained.
- ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition — lifecycle good-practice guidance.
- 21 CFR Part 11: Electronic Records; Electronic Signatures — applicable electronic-record and signature requirements.
- FDA Part 11, Electronic Records; Electronic Signatures — Scope and Application — September 2003 guidance on applicability and enforcement approach; predicate-rule obligations remain in effect.
- FDA Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers — October 2024 guidance for clinical investigations, including CROs.
- FDA General Principles of Software Validation — January 2002 guidance for medical-device software and software used in device production or the manufacturer’s quality system, not a blanket rule for clinical trial platforms.
- FDA Computer Software Assurance for Production and Quality Management System Software — February 2026 guidance for medical-device production and QMS software; distinct from clinical investigation system validation.
