Our services for spreadsheet validation
Which Excel Spreadsheets Require Validation?
The validation requirement follows the GxP risk, not the file size. Excel applications requiring validation include those that:
- Calculate or process test results, such as assay, yield or OOS assessments
- Record, trend or evaluate stability data
- Support batch release decisions
- Hold calibration and maintenance data
- Contain macros or VBA for automated GxP steps
- Generate data for regulatory reports or submissions
Administrative lists without product or patient relevance stay out of scope. We document the classification itself so that it holds up in an inspection.
Our Validation Process for Excel
1. Risk Assessment and Scoping
We inventory the spreadsheets in the area, classify them by GxP impact and complexity and set the scope per sheet. A plain calculation needs less evidence than a macro-driven evaluation. The approach follows the risk-based logic of GAMP 5 and complements your computer system validation.
2. Specification and Design
We write the User Requirements Specification and Functional Specification, as short as possible and as precise as necessary. We then harden the template: sheet and cell protection, locked formula ranges, input validation, version marking inside the document and a traceable record of changes.
3. Qualification and Validation (IQ/OQ/PQ)
We prepare the test protocols and execute them with you. Formulas and macros are tested with normal values, limit values and deliberately invalid entries so that error behaviour is documented too. The outcome is a validation report with a deviation list and a release recommendation.
4. Training and SOP Creation
We train users on the released tool and create or revise the SOP for use, maintenance and changes. This settles who distributes templates, how changes are requested and when a periodic review falls due.
Clarify scope?
Book an intro callLeistungs-Wegweiser
Welche Ausgangslage beschreibt Ihr Vorhaben?
Wählen Sie die Ausgangslage. Sie erhalten einen fokussierten Startpunkt mit Vertiefungen und Kontaktweg.
Vom Erstgespräch zum Plan
Wir klären Umfang, Rollen, Risiken und regulatorischen Rahmen und schlagen einen belastbaren Fahrplan vor.
Finding schließen
Root Cause, CAPA und Nachweise strukturiert aufbauen und QA-Abschluss vorbereiten.
Programm statt Einzelprojekt
PMO, Change Control und einheitliche Vorlagen über viele parallele Vorhaben hinweg.
Excel is the most frequently overlooked GxP system in pharma and chemicals. Spreadsheets calculate assay results, hold stability series, evaluate calibrations and support release decisions without ever having been managed as a computerised system.
Referenz: Case Story: ESSV sample management. Case Story lesen
What You Receive
Which deliverables do you need first?
Book an intro callUmfang klären?
Erstgespräch vereinbarenOur approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps
Why Validate Excel Spreadsheets?
Excel is the most frequently overlooked GxP system in pharma and chemicals. Spreadsheets calculate assay results, hold stability series, evaluate calibrations and support release decisions without ever having been managed as a computerised system.
The weak points are well known: formulas reachable through unprotected cells, copied templates circulating in several versions, no record of who changed which value and when. That is exactly what the data integrity requirements target.
EU GMP Annex 11 and 21 CFR Part 11 do not distinguish by software vendor. As soon as a spreadsheet creates or processes GxP data, the same requirements for specification, testing, access control and audit trail apply as for a LIMS.
Validate Excel or Build a Web App?
A shared Excel file can be validated and remains a sensible solution for clearly bounded tasks. However, when several people need to work concurrently, roles and permissions must be separated or file copies accumulate on network shares, a modern web app should also be assessed. The proven business logic of the spreadsheet is not discarded. It is transferred into a central application under controlled conditions.
| Criterion | Validated Excel | Modern Web App |
|---|---|---|
| Multi-user operation | Concurrent editing and file locks depend on the storage and Office configuration. | Users work concurrently in one central system without distributed copies on shares. |
| Roles and permissions | Sheet, cell and file protection provide limited and often coarse controls. | Roles can be differentiated by function, record and process step. |
| Audit trail | Change records require additional procedures and a controlled environment. | Relevant changes can record the user, time, old value, new value and reason. |
| Versioning | Template versions and completed files must be separated through robust procedures. | Application versions and controlled releases are managed centrally. |
| Traceability | Requirements, formulas and tests are linked through separate documents. | Requirements, functions, tests and releases can be assigned consistently. |
| Best fit | A bounded, stable calculation with few users and controlled file handling. | A collaborative process with several roles, frequent changes or a central data set. |
Our GxP software development can use the existing spreadsheet logic as its starting point. AI-supported development accelerates engineering and documentation, but it does not replace the subject matter risk assessment, the validation judgement or QA release. The scope remains risk-based and aligned with Annex 11 and Part 11. The related computer system validation is considered from the outset.
Our case story on a web app delivered in 270 hours shows how an existing Access solution was transferred to a web application within a clearly bounded effort. We decide whether a validated Excel file or a web app is appropriate for your process based on user count, criticality, rate of change and operating model. Excelsheet validation expressly remains part of our service.
Regulatory framework: EU GMP, ICH and FDA references
Spreadsheets are governed by the same regulations as any other GxP system.
- EU GMP Annex 11: requires risk management, specification, testing, access control and an audit trail for computerised systems.
- 21 CFR Part 11: governs electronic records and signatures, including the ability to produce copies and to trace changes.
- ISPE GAMP 5, 2nd Edition: provides the categorisation and the risk-based level of test depth. Macro-driven sheets usually sit in Category 5.
How the data integrity requirements interact in detail is covered by our Data Integrity service. If the sheet belongs to a piece of equipment, Equipment and Facility Qualification applies in addition.