Validation & Evidence
When Can Unscripted Testing Support GxP Computerised System Assurance?
Unscripted testing is not the absence of a test strategy. It replaces a prewritten sequence of steps with a defined assurance objective and a competent tester who explores the relevant scenarios or failure modes. The retained evidence still has to show what claim was challenged and why the result is acceptable.
FDA's February 2026 Computer Software Assurance guidance explicitly describes scenario testing and error guessing as unscripted testing methods for software used in medical-device production or quality management systems. The guidance is important evidence for the method, but its regulatory scope should not be silently extended to every pharmaceutical computerised system.
Start with the claim and risk
Before execution, define the intended use or function being assured, the relevant risk and the conditions that matter to the claim. Examples include demonstrating that a workflow remains controlled through realistic user variation, challenging a low-code configuration for foreseeable misuse, or probing error handling around a noncritical automation.
Do not use "exploratory" as permission to test whatever happens to come to mind. The tester should know the process purpose, important data, roles, boundaries and failure conditions. A short charter can state the objective, scope, data, environment and risks without prescribing every click.
Make the execution record reconstructable
FDA's final guidance identifies retained information for unscripted scenario testing and error guessing, including intended use, risk analysis, a summary of the features or failure modes tested, issues found, an acceptability conclusion, tester identity and date, plus review and approval when appropriate.
For a broader GxP context, the same evidence logic is useful even where FDA CSA is not the governing regulation. The record should let another competent person understand what was exercised, what was observed, which problems appeared and why the conclusion follows.
Capture failures as they occur. Preserve screenshots, logs, record identifiers or other objective evidence where they materially support the observation. Do not rewrite the session afterward so it looks like a preplanned script.
Know where unscripted testing is strong
Unscripted methods are particularly useful where the value comes from variation and challenge:
- realistic scenario exploration across several user choices;
- exception and recovery paths;
- boundary values and combinations that are hard to enumerate in advance;
- error guessing based on known product or process weaknesses;
- usability or workflow behaviour where rigid scripts can hide operator problems.
They can complement scripted verification. One method does not need to replace the other.
Know where a script may still be the better control
Use more prescriptive execution where exact reproducibility is part of the objective, where a formal sequence is needed to prove a specific configuration, where evidence must be repeated consistently across environments, or where a protocol itself is a required controlled artefact under the organisation's procedure.
The decision should be based on the assurance claim and risk, not on a belief that scripted evidence is inherently stronger or that unscripted evidence is inherently more modern.
Handle failures without erasing the original observation
If unscripted testing finds a defect or unexpected state, record the condition, affected claim and immediate evidence before correction. Subsequent retesting should be traceable to the original issue. The absence of a scripted expected-result field does not remove the need to distinguish an acceptable observation from a failure requiring disposition.
ICH Q9(R1) supports risk-based and proportionate quality-risk management. Using that principle to choose the formality of software assurance evidence is practitioner interpretation, not an ICH prescription for a particular software-testing technique.
Important boundaries
FDA CSA is cited within its stated medical-device production and quality-management-system scope. EU GMP Annex 11 continues to require validation and controlled lifecycle evidence for GMP computerised systems, but it does not prescribe scenario testing or error guessing by name. An organisation should align the method with its own applicable regulations and quality system.
Sources
- FDA, Computer Software Assurance for Production and Quality Management System Software: final February 2026 guidance describing risk-based assurance methods, including scenario testing and error guessing, within its stated scope.
- European Commission, EU GMP Annex 11: Computerised Systems: GMP expectations for validation, lifecycle control and appropriate evidence for computerised systems.
- ICH Q9(R1), Quality Risk Management: principles for science-based and proportionate quality-risk management.