1. Planning
Validation plan (VP)
Scope and strategy of the validation, responsibilities, and the client's own procedures that apply.
A system that complies because it was documented afterwards is fragile. One that complies because it was designed that way withstands a new version, a new supplier and a new inspector.
Not every system needs the same control.
A pharmaceutical company has systems that affect product quality or patient safety, and systems that handle purchasing or meeting room bookings. Treating them the same is an expensive mistake in both directions.
The first decision in every project is which category the system belongs to and what evidence has to be produced as a result. That decision is documented and justified, because it is the first one you will be asked to explain.
What you receive besides the software.
This is the documentation index: eleven documents in four phases, from planning to closure. Our method shows at what point in the project each one is delivered.
1. Planning
Scope and strategy of the validation, responsibilities, and the client's own procedures that apply.
1. Planning
Written with your users. Each requirement has its own code and is traceable to the test that verifies it.
2. Design
What the system does and how it is built inside.
2. Design
The risks of each requirement to the patient, the product and data integrity, and the phase in which their control is verified.
2. Design
Checks that the design meets each requirement. Each test takes the code of the requirement it verifies: URS-042 → DQ-042.
Includes its protocol, the execution with the evidence, the deviation log and its report.
3. Execution
Verifies that the system is installed according to its specifications.
Includes its protocol, the execution with the evidence, the deviation log and its report.
3. Execution
Verifies that each function operates as specified.
Includes its protocol, the execution with the evidence, the deviation log and its report.
3. Execution
Verifies the workflows end to end, with several users, screenshots and the audit trail.
Includes its protocol, the execution with the evidence, the deviation log and its report.
4. Closure
Where each risk stands after testing, and the justification for closing it.
4. Closure
From each requirement to the test that proves it is met.
4. Closure
The result of the validation. The system goes into production with it, not with a promise to write it.
What we apply depending on the scope of the project.
In Spain and Portugal the European Union rules apply. In Latin America, each country's own regulation applies, and it is best read alongside these common references:
Choose one or more countries. With none chosen, all of them are shown.
| Country | Authority and good practice standard | Computerized systems | Personal data |
|---|---|---|---|
| Spain | AEMPS · EU Good Manufacturing Practice, EudraLex Volume 4 | Annex 11, computerized systems | GDPR and Organic Law 3/2018 |
| Portugal | INFARMED · EU Good Manufacturing Practice, EudraLex Volume 4 | Annex 11, computerized systems | GDPR and its national law |
| Brazil | ANVISA · RDC 658/2022 | IN 134/2022, complementary good practices for computerized systems. Guide 33/2020 as a reference | LGPD, Law 13.709/2018 |
| Mexico | COFEPRIS · NOM-059-SSA1-2015, amended in 2025 | Section 9.13, validation of computer systems | Federal Law on the Protection of Personal Data Held by Private Parties, 2025 |
| Argentina | ANMAT · Disposition 4159/2023, which adopts the PIC/S guide | Annex 6, computerized systems | Law 25.326 |
| Colombia | INVIMA · Resolution 1160 of 2016 | No specific annex: general requirements for electronic records and validation | Law 1581 of 2012 |
| Chile | ISP · Technical Standard 127 | Annex 1, validation, which includes computerized systems | Law 19.628. Law 21.719 replaces it on December 1, 2026 |
| Peru | DIGEMID · Supreme Decree 021-2018-SA, Good Manufacturing Practice Manual | Assessed in each project according to the Manual | Law 29733 |
| Uruguay | MSP · Decree 440/016, which adopts Mercosur GMC Resolution 15/09, based on the WHO guide | Requirements of the WHO guidance on automated systems and electronic data | Law 18.331 |
| Paraguay | DINAVISA · Resolution 183/2026, which adopts the PIC/S guide | PIC/S Annex 11, computerized systems, and Annex 15 | Law 7593/2025, in force from November 2027 |
| Costa Rica | Ministry of Health · Central American Technical Regulation RTCA 11.03.42:07 | Sections 16.4 j), computer systems, and 11.1.6, electronic data | Law 8968 |
| Panama | National Directorate of Pharmacy and Drugs (MINSA) · RTCA 11.03.42:07, adopted by Executive Decree 267 of 2014 | Sections 16.4 j) and 11.1.6 of the RTCA | Law 81 of 2019 |
| Guatemala | MSPAS, Department of Regulation and Control of Pharmaceutical Products · RTCA 11.03.42:07 | Sections 16.4 j) and 11.1.6 of the RTCA | No specific law |
13 countries
The dates of the standards on this page, from the Annex 22 consultation to the data laws coming into force.
The European Commission published it for consultation together with the revision of Annex 11 and Chapter 4.
View the Annex 22 guideIts section 9.13 governs the validation of computer systems.
Mexico's personal data protection law, from 2025.
The prohibited practices apply, along with the duty to promote AI literacy among the staff who use or build AI.
For medicine development: a shared governance framework for the models involved in the medicine lifecycle.
It is aimed at medical devices. For drugs, the same risk-based approach is the one GAMP 5 Second Edition takes.
Resolution 183/2026, with Annex 11, computerized systems, and Annex 15.
Industry experts discuss the control strategy for allowing dynamic, probabilistic and generative AI models.
View where the text is headingPeople must be told that they are interacting with an AI, and the content it generates must be marked. Enforcement by the authorities begins.
It points to a technology-neutral annex: the intended use, the risk and the effectiveness of the controls are what decide.
EudraLex Volume 4 contains Annexes 1 to 21. Checked against the official source.
Chile's personal data protection law changes.
Paraguay's personal data protection law.
Requirements for high-risk systems, such as recruitment and workforce management. The Digital Omnibus package postponed them from August 2026.
Requirements for AI that is part of regulated products, such as medical devices assessed by a notified body.
15 dates
We work it out with you before starting, so you validate neither too much nor too little.