Navata
← All Library

Validation & Evidence

When Can Unscripted Testing Support GxP Computerised System Assurance?

AI-assisted research and drafting · Practitioner reviewed by Rohith Karanam Sreedhar · 15 September 2026

Library content is researched and drafted with AI assistance and reviewed by a Navata practitioner before publication. For original analysis and long-form practitioner perspectives, visit Navata Insights →

Unscripted testing is not the absence of a test strategy. It replaces a prewritten sequence of steps with a defined assurance objective and a competent tester who explores the relevant scenarios or failure modes. The retained evidence still has to show what claim was challenged and why the result is acceptable.

FDA's February 2026 Computer Software Assurance guidance explicitly describes scenario testing and error guessing as unscripted testing methods for software used in medical-device production or quality management systems. The guidance is important evidence for the method, but its regulatory scope should not be silently extended to every pharmaceutical computerised system.

Start with the claim and risk

Before execution, define the intended use or function being assured, the relevant risk and the conditions that matter to the claim. Examples include demonstrating that a workflow remains controlled through realistic user variation, challenging a low-code configuration for foreseeable misuse, or probing error handling around a noncritical automation.

Do not use "exploratory" as permission to test whatever happens to come to mind. The tester should know the process purpose, important data, roles, boundaries and failure conditions. A short charter can state the objective, scope, data, environment and risks without prescribing every click.

Make the execution record reconstructable

FDA's final guidance identifies retained information for unscripted scenario testing and error guessing, including intended use, risk analysis, a summary of the features or failure modes tested, issues found, an acceptability conclusion, tester identity and date, plus review and approval when appropriate.

For a broader GxP context, the same evidence logic is useful even where FDA CSA is not the governing regulation. The record should let another competent person understand what was exercised, what was observed, which problems appeared and why the conclusion follows.

Capture failures as they occur. Preserve screenshots, logs, record identifiers or other objective evidence where they materially support the observation. Do not rewrite the session afterward so it looks like a preplanned script.

Know where unscripted testing is strong

Unscripted methods are particularly useful where the value comes from variation and challenge:

  • realistic scenario exploration across several user choices;
  • exception and recovery paths;
  • boundary values and combinations that are hard to enumerate in advance;
  • error guessing based on known product or process weaknesses;
  • usability or workflow behaviour where rigid scripts can hide operator problems.

They can complement scripted verification. One method does not need to replace the other.

Know where a script may still be the better control

Use more prescriptive execution where exact reproducibility is part of the objective, where a formal sequence is needed to prove a specific configuration, where evidence must be repeated consistently across environments, or where a protocol itself is a required controlled artefact under the organisation's procedure.

The decision should be based on the assurance claim and risk, not on a belief that scripted evidence is inherently stronger or that unscripted evidence is inherently more modern.

Handle failures without erasing the original observation

If unscripted testing finds a defect or unexpected state, record the condition, affected claim and immediate evidence before correction. Subsequent retesting should be traceable to the original issue. The absence of a scripted expected-result field does not remove the need to distinguish an acceptable observation from a failure requiring disposition.

ICH Q9(R1) supports risk-based and proportionate quality-risk management. Using that principle to choose the formality of software assurance evidence is practitioner interpretation, not an ICH prescription for a particular software-testing technique.

Important boundaries

FDA CSA is cited within its stated medical-device production and quality-management-system scope. EU GMP Annex 11 continues to require validation and controlled lifecycle evidence for GMP computerised systems, but it does not prescribe scenario testing or error guessing by name. An organisation should align the method with its own applicable regulations and quality system.

Sources