Qualification & Validation

Excelsheet Validation: GxP-Compliant Excel Spreadsheets in Pharma

A spreadsheet that captures GxP-relevant data, calculates results or supports decisions is a computerised system and therefore subject to validation. We classify your spreadsheets on a risk basis, validate the critical ones and document the outcome for inspection under EU GMP Annex 11, 21 CFR Part 11 and GAMP 5.

Our services for spreadsheet validation

Which Excel Spreadsheets Require Validation?

The validation requirement follows the GxP risk, not the file size. Excel applications requiring validation include those that:

  • Calculate or process test results, such as assay, yield or OOS assessments
  • Record, trend or evaluate stability data
  • Support batch release decisions
  • Hold calibration and maintenance data
  • Contain macros or VBA for automated GxP steps
  • Generate data for regulatory reports or submissions

Administrative lists without product or patient relevance stay out of scope. We document the classification itself so that it holds up in an inspection.

Our Validation Process for Excel

1. Risk Assessment and Scoping

We inventory the spreadsheets in the area, classify them by GxP impact and complexity and set the scope per sheet. A plain calculation needs less evidence than a macro-driven evaluation. The approach follows the risk-based logic of GAMP 5 and complements your computer system validation.

2. Specification and Design

We write the User Requirements Specification and Functional Specification, as short as possible and as precise as necessary. We then harden the template: sheet and cell protection, locked formula ranges, input validation, version marking inside the document and a traceable record of changes.

3. Qualification and Validation (IQ/OQ/PQ)

We prepare the test protocols and execute them with you. Formulas and macros are tested with normal values, limit values and deliberately invalid entries so that error behaviour is documented too. The outcome is a validation report with a deviation list and a release recommendation.

4. Training and SOP Creation

We train users on the released tool and create or revise the SOP for use, maintenance and changes. This settles who distributes templates, how changes are requested and when a periodic review falls due.

Clarify scope?

Book an intro call

Leistungs-Wegweiser

Welche Ausgangslage beschreibt Ihr Vorhaben?

Wählen Sie die Ausgangslage. Sie erhalten einen fokussierten Startpunkt mit Vertiefungen und Kontaktweg.

Excel is the most frequently overlooked GxP system in pharma and chemicals. Spreadsheets calculate assay results, hold stability series, evaluate calibrations and support release decisions without ever having been managed as a computerised system.

Referenz: Case Story: ESSV sample management. Case Story lesen

What You Receive

Inventory of GxP-relevant spreadsheets with risk classification and rationale
URS and Functional Specification for each validated sheet
Hardened template with cell protection, input checks and version marking
IQ, OQ and PQ test protocols including executed evidence
Validation report with deviations, assessment and release recommendation
Draft SOP for use, change control and periodic review

Which deliverables do you need first?

Book an intro call

Umfang klären?

Erstgespräch vereinbaren

Our approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps

Why Validate Excel Spreadsheets?

Excel is the most frequently overlooked GxP system in pharma and chemicals. Spreadsheets calculate assay results, hold stability series, evaluate calibrations and support release decisions without ever having been managed as a computerised system.

The weak points are well known: formulas reachable through unprotected cells, copied templates circulating in several versions, no record of who changed which value and when. That is exactly what the data integrity requirements target.

EU GMP Annex 11 and 21 CFR Part 11 do not distinguish by software vendor. As soon as a spreadsheet creates or processes GxP data, the same requirements for specification, testing, access control and audit trail apply as for a LIMS.

Validate Excel or Build a Web App?

A shared Excel file can be validated and remains a sensible solution for clearly bounded tasks. However, when several people need to work concurrently, roles and permissions must be separated or file copies accumulate on network shares, a modern web app should also be assessed. The proven business logic of the spreadsheet is not discarded. It is transferred into a central application under controlled conditions.

Continue with Excel selectively
For a small, stable user group, we harden and validate the existing spreadsheet. Formulas, protection, versioning and change control remain governed and traceable.
Establish the existing logic as a web app
For growing or collaborative processes, we transfer rules and calculations into a centrally operated application with user management, audit trail and controlled releases.
Criterion Validated Excel Modern Web App
Multi-user operation Concurrent editing and file locks depend on the storage and Office configuration. Users work concurrently in one central system without distributed copies on shares.
Roles and permissions Sheet, cell and file protection provide limited and often coarse controls. Roles can be differentiated by function, record and process step.
Audit trail Change records require additional procedures and a controlled environment. Relevant changes can record the user, time, old value, new value and reason.
Versioning Template versions and completed files must be separated through robust procedures. Application versions and controlled releases are managed centrally.
Traceability Requirements, formulas and tests are linked through separate documents. Requirements, functions, tests and releases can be assigned consistently.
Best fit A bounded, stable calculation with few users and controlled file handling. A collaborative process with several roles, frequent changes or a central data set.

Our GxP software development can use the existing spreadsheet logic as its starting point. AI-supported development accelerates engineering and documentation, but it does not replace the subject matter risk assessment, the validation judgement or QA release. The scope remains risk-based and aligned with Annex 11 and Part 11. The related computer system validation is considered from the outset.

Our case story on a web app delivered in 270 hours shows how an existing Access solution was transferred to a web application within a clearly bounded effort. We decide whether a validated Excel file or a web app is appropriate for your process based on user count, criticality, rate of change and operating model. Excelsheet validation expressly remains part of our service.

Regulatory framework: EU GMP, ICH and FDA references

Spreadsheets are governed by the same regulations as any other GxP system.

  • EU GMP Annex 11: requires risk management, specification, testing, access control and an audit trail for computerised systems.
  • 21 CFR Part 11: governs electronic records and signatures, including the ability to produce copies and to trace changes.
  • ISPE GAMP 5, 2nd Edition: provides the categorisation and the risk-based level of test depth. Macro-driven sheets usually sit in Category 5.

How the data integrity requirements interact in detail is covered by our Data Integrity service. If the sheet belongs to a piece of equipment, Equipment and Facility Qualification applies in addition.

FAQ on Excelsheet Validation

Does every Excel file need to be validated?
No. Validation is risk-based. Spreadsheets that create, process or retain GxP-relevant data and can affect product quality or patient safety must be validated. Administrative lists without that relevance require no formal validation, but they do require a documented classification.
What regulatory requirements apply to Excel validation?
The governing documents are EU GMP Annex 11 for computerised systems, 21 CFR Part 11 for electronic records and signatures, and GAMP 5 for risk-based test depth. Simple calculation templates usually sit in GAMP Category 4, macro or VBA-driven applications in Category 5.
How is change control handled for validated Excel spreadsheets?
Every change to the template, such as a new formula or a modified cell structure, runs through the formal change control process. A risk assessment decides whether a full re-validation is required or whether a targeted regression test of the affected functions is sufficient.
What are the four main steps in the validation lifecycle of an Excel spreadsheet?
First, planning with a validation plan and URS. Second, specification and development with a design specification and a hardened template. Third, qualification with IQ, OQ and PQ tests and a validation report. Fourth, operation with release, training, change control and periodic review.

Next Step: Sheet Inventory and Risk Classification

Tell us the area, the number of spreadsheets and whether macros are in use. We propose the scope and the order of validation.

Get in Touch