Compliance explainerUpdated September 28, 2026

Computer system validation: whose job is it, actually

Computer system validation (CSV) is documented evidence that a computerized system does what it claims to, consistently, and it is the sponsor's responsibility, not something a vendor completes on the sponsor's behalf. This page covers what CSV actually needs and what Capture provides to support your own validation and UAT.

  • Validation is shared, not outsourced
  • Documentation for sponsor UAT (Enterprise)
  • Field-level audit trail from day one

Free sandbox · No credit card · 21 CFR Part 11 aligned

Weight changed 68.0 to 68.5 kg

Site coordinator · Reason: Transcription error

9f2c…a71e

Query Q-0014 answered on Weight

Site coordinator · Reason: Source checked

4b8d…c203

Vital signs form locked

Data manager · Reason: Visit cleaned

e61a…58f0
Verify chain Intact

Shared

responsibility: software provider and sponsor both have a role

Field-level

audit trail: timestamp, user, old value, new value, reason

2-step

e-signature verification: OTP-confirmed signer, then countersignature

Enterprise

tier includes documentation to support sponsor validation and UAT

The concept

CSV is documented proof, not a certificate

Computer system validation means documenting that a system performs as intended for its specific, intended use, consistently and reproducibly. It is not a certificate a vendor hands you. It is evidence your own quality team assembles: intended use, risk assessment, and testing that the system does what your SOPs say it should, for how your study specifically uses it.

  • CSV is study- and use-specific, not a one-time universal stamp for a piece of software.
  • A vendor can provide documentation and a stable, controlled system. The validation exercise itself is the sponsor's.
  • This is true of every EDC, not something specific to Capture.
Electronic signature

Meaning of signature

I have reviewed this adverse event and confirm the assessment of seriousness, severity and causality.

Signer

Dr. A. Ozola, PI

Password

••••••••••

Verified on the serverAutofill blockedSingle-use token
Sign

What to check

What a validated system actually needs underneath it

A real audit trail, not an editable log

Field-level history on every record: timestamp, user identity, old value, new value and reason for change, not modifiable from the UI.

Verified electronic signatures

OTP-verified participant signature and password-reauthenticated investigator countersignature, each cryptographically linked to the document content at signing time.

Role-based access control

Researcher, site coordinator and admin roles, with PII segregation and row-level security enforcing what each role can see.

A stable, controlled build process

Forms move through a draft-to-approved lifecycle; only approved forms reach the live casebook.

Documentation you can hand your quality team

Enterprise customers get documentation and implementation assistance to support their own validation and UAT process.

Who does what

Validation responsibility, split out

Audit trail and e-signatures
Built in, running from your first entry
Confirm they match your SOPs and risk assessment
Stable, versioned system
Draft/approved form lifecycle, controlled releases
Document your own change control and re-validation triggers
Test evidence
A free sandbox to run your own test scripts against
Write, execute and sign off your UAT scripts
Independent security audit status
Not currently published; confirm before relying on it
Factor into your own vendor risk assessment

Before you switch

What quality teams ask before validating a new platform

Cost

Free sandbox to run your own UAT scripts against, no credit card required.

Compliance

Capture is not "CSV compliant" as a label. It gives you a stable, audited system and, on Enterprise, documentation to support your own validation; the validation exercise itself is yours to run.

Setup time

Sandbox and production environments are separate from the start, so validation testing does not touch live data.

Migration

Bring an existing validated workflow's documentation approach across; the underlying controls (audit trail, e-signatures, RBAC) are the same shape.

Support

Email support, typically under 24 hours, plus training and implementation assistance on Enterprise.

Start your UAT in a free sandbox

No credit card, no sales call. Bring your own test scripts.

Start your UAT free

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

What is computer system validation (CSV)?

CSV is documented evidence that a computerized system performs consistently and as intended for its specific use. It is assembled by the system's user (the sponsor), not delivered as a one-time certificate from a vendor.

Is Capture "CSV compliant"?

No software is validated in the abstract; validation is study- and use-specific and is the sponsor's responsibility. Capture provides a stable, audited system and, on Enterprise, documentation to support your own validation and UAT.

Does CSV require SOC 2 certification?

They are related but distinct. SOC 2 is an independent audit of a provider's own controls. Its current status is not published on our marketing site; confirm directly with us if that is a hard requirement for your program.

What documentation does Capture provide for validation?

Enterprise customers receive documentation, training and implementation assistance to support their own validation and UAT process.

How is this different from the 21 CFR Part 11 checklist?

Part 11 sets the rules for electronic records and signatures. CSV is the validation process that proves your specific system, as you use it, actually meets them. See our Part 11 checklist for the rules themselves.

Can I run my own UAT scripts before committing?

Yes. The free sandbox includes every feature with sample data, no credit card and no time limit.

Start your UAT in a free sandbox

No credit card, no sales call. Bring your own test scripts.

Start your UAT free