info@trustbridge-compliance.com
Home / Frameworks / DRIVE
CSV to CSA

DRIVE

You’ve decided to move from CSV to CSA. DRIVE is the operating discipline for that journey: it turns the guidance into changed behaviour across fifteen or twenty sites without losing control, and it tells you what to do first.

The five disciplines · critical thinking, documented, underneath all five
D
Documentation
R
Risk management
I
Implementation
V
Vendor assessment
E
Evidence management
DRIVE: Documentation, Risk management, Implementation, Vendor assessment, Evidence management.

The CSA risk decision, in four steps

Inside DRIVE sits the decision that does the real work, applied at the function level rather than the system level.

1 · Impact Quality & safety? 2 · Method Custom / Configured / Out-of-box 3 · Risk rating Rate 1 to 5 4 · Right testing Sized to the risk
Impact, implementation method, risk rating, right-sized testing, judged at the function level.

CSV and CSA, side by side

 Traditional CSVCSA with DRIVE
Unit of riskThe whole systemThe function or feature
EffortSpread evenly, document-heavyConcentrated where risk is
TestingScripted by defaultScripted, unscripted or vendor evidence, by risk
Supplier evidenceRe-created in-houseAssessed and leveraged
EngineTemplates and volumeCritical thinking, documented

What changes

Documentation falls by 25 to 50% on common system categories, effort concentrates where risk is, and the model extends cleanly to AI-enabled systems next. In a comparable multi-site programme, a Modular Qualification Architecture built on this thinking produced more than €10M in annual savings and cut equipment qualification cycle times by 45%.

Key takeaways

  • CSA is a return to validation's true intent, not a new methodology.
  • Risk is judged at the function level, not the system level.
  • Critical thinking, documented, is the engine. The matrix is just the scaffold.
Questions people ask

Questions I get asked about DRIVE

What does the DRIVE framework stand for?

Documentation, Risk management, Implementation, Vendor assessment and Evidence management, with critical thinking documented underneath all five. Together the five disciplines turn the FDA’s Computer Software Assurance guidance into changed validation behaviour across an estate of fifteen or twenty sites, without losing control and without waiting for a perfect template set.

How does the CSA risk decision work in practice?

In four steps, applied at the function level rather than the system level. Judge the impact on quality and patient safety, identify the implementation method (custom, configured or out-of-box), rate the risk 1 to 5, then size the testing to match. Effort follows consequence rather than habit.

How much documentation does CSA remove?

On common system categories, documentation falls by 25 to 50% once risk is judged at the function level and supplier evidence is assessed instead of re-created in-house. The record that remains is smaller and sharper, and it proves control exactly where the risk sits.

Is the FDA’s CSA guidance final?

Yes. The FDA finalised its Computer Software Assurance guidance in September 2025, after the 2022 draft, and updated it in February 2026 to align with the QMSR. GAMP 5 second edition points the same way. The open question is execution: turning that guidance into how fifteen or twenty sites actually validate.