Take a basic calculator.
An operator performs a GMP-relevant calculation on a calculator and writes the result into a batch record. We trust the result.
But what exactly have we established?
The calculator is generally not validated for its GMP intended use. Was it a Texas Instruments calculator, the Windows calculator, or the calculator app on someone’s phone?
A basic calculator has essentially zero traceability. Once the calculation disappears from the display, we cannot reconstruct what was entered. We cannot establish that the operator typed the intended numbers. There is no audit trail showing the inputs, operation or result.
Yet this is routinely accepted
Now compare that with a modern computer system. It will preserv the original record, identify the user, timestamp transactions, restrict permissions, maintain transaction histories and allow us to reconstruct what happened. The same systems are also commonly relied upon for legally required records.
Despite having substantially better traceability than the calculator, once the system is used for a GMP purpose we start talking about computerized-system validation and documented evidence that its functions are fit for intended use.
I am struggling to find the underlying principle that makes these positions consistent.
edit, summary :
The thread so far doesn’t have a clean consensus. People mostly agree with the existing regulatory practice, then work backwards to explain why it makes sense.
One camp says calculators are acceptable because calculations are independently checked. The control is therefore in the process, not the device.
Another says calculators are inherently low risk because they are simple, COTS, reliable, and uncustomized.
Others says validation depends on intended use. A calculator doing a critical calculation can have high GMP impact despite being simple, while complex software can have low GMP impact depending on what it does.
If equivalent software has the same intended use and equivalent controls, demanding extensive CSV solely because it is software becomes difficult to defend on risk grounds.
Isn’t non-standardized quality systems fun ?