Home > Products > Software Validation for Regulated Labs

Your LabKey software, validated three times a year.

Adding validation to your software means that your team can trust your data, and when auditors ask questions, your team is ready. LabKey’s validation package provides regulated labs with documented, structured evidence that their system does what it needs to do, and keeps that evidence current through each of our three major releases a year.

Validation at LabKey is available for add-on for Sample Manager Professional, LIMS Starter, and LIMS Enterprise.

Two packages are available: a standard validation pack for the LabKey platform (Phase 1), and an optional configuration-specific package for your deployment (Phase 2).

Contact Us

Why Validation Matters

A validated system means your team trusts the data it produces and your lab is ready when auditors ask questions.
For labs working under GxP requirements or alongside CROs, it also demonstrates that your quality standards match theirs. Getting validation right from the start is significantly less disruptive than addressing gaps after the fact.

Validation supports labs that need:

  • Documented confidence in the data your system produces
  • A lab that’s ready when auditors ask questions, not scrambling to respond
  • Evidence that your quality standards meet CRO expectations
pattern right

What's included in LabKey Validation Package (Phase1)?

  • Validation Plan (VP):
    Defines the scope, approach, and objectives for validating your LabKey system, covering both the initial delivery and ongoing maintenance through each release.
  • System Requirements Specification (SRS):
    Documents all available functionality in the LabKey platform, establishing the baseline against which all testing is performed.
  • Risk Assessment (RA):
    Evaluates potential impacts associated with system requirements, identifying where to focus testing effort and how risks are mitigated.
  • Operational Qualification (OQ):
    Pre-built functional testing of core system capabilities, delivered with documented results. Includes test cases covering electronic records and electronic signatures aligned to 21 CFR Part 11 and EudraLex Volume 4 Annex 11.
  • Compliance Assessment (CA):
    Summarizes how LabKey supports your lab's alignment with 21 CFR Part 11, EudraLex Volume 4 Annex 11, and data integrity requirements.
  • Traceability Matrix (TMX):
    Links every requirement in the SRS to its corresponding test, providing documented evidence that nothing has been missed.
  • Impact Assessment (IA):
    Provided with each new release, evaluating what has changed and where existing documentation or testing requires updating.
  • Validation Summary Report (VSR):
    The final approval document for the validation pack, confirming all activities are complete and the system meets its validated state.
pattern right

What is included with the Configuration-Specific Validation Package (Phase 2)?

  • System Configuration Specification (SCS):
    Documents the configuration settings specific to your implementation.
  • Performance Qualification (PQ):
    Risk-based testing of your specific configuration, workflows, and intended use.
  • Final Summary Report (FSR):
    Summary of all validation activities completed.
  • Installation Qualification (IQ):
    Qualifies your specific test and production environments.

How it works

Pre-built documentation

Validation plan, requirements, risk assessment, and traceability matrix provided from the start. These documents are maintained and updated with each release, so your documentation stays current without rebuilding from scratch.

Functional testing

Core system capabilities, including sample types, storage, workflows, and assays, are tested against expected behavior and documented as delivered. This pre-built testing gives your team a solid foundation and reduces the scope of configuration-specific testing that follows.

Workflow testing

An optional additional phase covering your specific configuration, workflows, and intended use. Testing is scoped to how your team has deployed the system, not the full platform, keeping effort proportionate to your actual risk.

Release impact assessments

Each of three annual releases includes an assessment identifying what changed and where retesting is needed. The impact assessment distinguishes changes that affect your validated state from those that don’t, keeping retesting focused on what actually matters.

GAMP 5 aligned

Documentation and testing methodology follows GAMP 5 2nd Edition guidance and current US FDA guidance on computer software assurance. Testing also addresses electronic records and electronic signatures requirements under 21 CFR Part 11 and EudraLex Volume 4 Annex 11.

Ready to discuss validation?

Get in touch to discuss your lab’s validation requirements and which package fits your LabKey software needs.

Contact Us

LabKey Validation FAQ

Not every lab does. Validation is typically required for labs operating under GxP regulations, those managing data subject to regulatory review, or teams working with CROs that expect their partners to meet the same compliance standards. If you're unsure whether your environment requires it, that's a good conversation to have internally before you're facing an inspection.

Phase 1 validates that LabKey performs as the software is designed to — the platform as delivered, tested and documented. Phase 2 validates that your specific setup does what it's supposed to do for your lab, covering your configuration and intended use. Some labs need to purchase both; others choose to purchase Phase 1 and do their own Phase 2 internally.

It depends on your regulatory environment, how you've configured your system, and what your quality team needs to demonstrate to inspectors. Get in touch and we can help you work through what makes sense for your situation.

Labs on a validation package don't receive monthly software updates. Instead, updates are delivered three times a year, with each release fully validated before it reaches your environment.