- GxP
- The family of “good practice” regulations — manufacturing (GMP), laboratory (GLP), clinical (GCP) — that govern regulated records and systems.
- ALCOA+
- Data-integrity principles: attributable, legible, contemporaneous, original and accurate, plus complete, consistent, enduring and available.
- Data integrity
- The assurance that records are complete, consistent and accurate throughout their life — the point where GxP and security meet.
- Audit trail
- A secure, time-stamped record of who created, changed or deleted a record, and why; required to be on and protected.
- EU GMP Annex 11
- The EU’s GMP annex on computerised systems; a revised draft published in July 2025 adds a full security chapter.
- Annex 22
- A new draft EU GMP annex, published with the Annex 11 draft, on the use of artificial intelligence in GMP.
- 21 CFR Part 11
- The US FDA rule on electronic records and electronic signatures, including access controls and audit trails.
- Revised Schedule M
- India’s updated GMP requirements under the Drugs Rules, including a section on computerised systems.
- CSV
- Computer system validation — documented evidence that a computerised system does what it should, consistently.
- CSA
- Computer software assurance — a risk-based approach to that evidence; the FDA finalised its CSA guidance for device production and quality-system software in September 2025.
- GAMP 5
- ISPE’s widely used guide to a risk-based approach to compliant GxP computerised systems.
- LIMS · CDS · MES · QMS
- Laboratory information management, chromatography data, manufacturing execution and quality management systems — the GxP systems attackers reach most often.
- Requalification
- Re-establishing that a rebuilt or changed system is back in a validated state before its records are relied on.