# Validation Summary Report — Customer Template

> **TEMPLATE / NOT EXECUTED / NOT VALIDATION EVIDENCE**

## 1. Document control

- Report ID: CUSTOMER-ASSIGNED
- Protocol ID and approved version:
- System / product:
- Software release, build, and commit identifier:
- Configuration baseline:
- Environment / tenant identifier:
- Report author and date:
- Reviewers and approvers:

## 2. Purpose and intended use

Describe the exact intended use assessed by this report, the regulated processes and record types in scope, intended users, locations, integrations, and system boundaries.

## 3. Scope and exclusions

List included features, configurations, procedures, data flows, electronic-record and electronic-signature use, AI-supported functions, and explicit exclusions. State what the conclusion does not cover.

## 4. Applicable requirements and source baseline

Identify the customer-approved requirements baseline and authoritative-source versions used. Record qualified review of applicability. A requirements mapping alone is not evidence that a control is implemented or effective.

## 5. Risk-based assurance strategy

Summarize the intended-use process-risk analysis, reasonably foreseeable failures, risk controls, testing methods selected, and justification for the depth of assurance.

## 6. Tested baseline and prerequisites

Identify the exact application release, configuration, infrastructure, roles, integrations, browsers, time source, retention settings, backup controls, procedures, test data, and prerequisite qualification or training evidence.

## 7. Execution summary

| Measure | Planned | Executed | Passed | Failed | Not run | Not applicable |
| --- | ---: | ---: | ---: | ---: | ---: | ---: |
| Tests |  |  |  |  |  |  |

Summarize scripted, automated, scenario, exploratory, negative, security, recovery, compatibility, accessibility, and user-acceptance activities performed. Link each conclusion to controlled evidence.

## 8. Deviations, defects, and known anomalies

List every deviation and unresolved anomaly; describe investigation, impact on intended use and data integrity, correction, corrective action, retesting, residual risk, procedural control, and approved disposition.

## 9. Traceability reconciliation

Confirm whether every in-scope requirement and risk control has an approved test or other justified assurance activity and an acceptable result. Identify gaps and conditions.

## 10. Security, data integrity, and continuity

Summarize evidence for identity and access, auditability, electronic signatures where applicable, record copies, retention, encryption, backup, restore, monitoring, incident response, and disaster recovery.

## 11. AI-supported functions

Identify approved AI intended uses, prohibited actions, model and prompt versions, controlled retrieval sources, evaluation data, performance criteria, provenance, human-review controls, abstention/fallback behavior, monitoring, and change triggers. State that AI output does not replace qualified human decisions.

## 12. Training and operational readiness

Confirm that approved procedures, administrator and user training, support, monitoring, access review, backup oversight, incident handling, periodic review, and change-control responsibilities are effective before release.

## 13. Conclusion

Select one and provide objective rationale:

- [ ] Accepted for the stated intended use and exact baseline.
- [ ] Accepted with documented conditions and controls.
- [ ] Not accepted for production use.

This conclusion applies only to the identified intended use, release, configuration, environment, procedures, integrations, and evidence. It is not a universal certification, regulatory approval, or guarantee of an audit outcome.

## 14. Approval

| Role | Name | Decision | Signature / controlled approval | Date |
| --- | --- | --- | --- | --- |
| Business process owner |  |  |  |  |
| Quality assurance |  |  |  |  |
| System owner |  |  |  |  |
| Regulatory / compliance reviewer, if applicable |  |  |  |  |
| Security / privacy reviewer, if applicable |  |  |  |  |

## 15. Maintaining the validated state

Define monitoring, access review, backup and restore review, incident and deviation handling, periodic review, supplier review, release/change notifications, change-impact assessment, re-testing triggers, retirement, archival, and record-retention responsibilities.
