- We use Confluence for our eQMS, which is supplemented with various apps for additional functionality. For instance, we use the QC - Read and Understood app to track whether employees have read and understood certain pages. How should we validate these apps? What requirements should we include?
- Additionally, we need to determine the schedule for revalidating these systems. My suggestion is to revalidate apps with a medium or high-risk rating every three months, while those with a low-risk rating should be revalidated annually. The standard does not specify how often revalidation should occur, so I'm unsure about the appropriate frequency.
- If an application claims to have a default functionality that has been widely used and verified by many users, does this mean we do not need to validate it? For example, consider the requirement "Any user with access to Jira can create issues." Since this is a well-known, standard feature used by all Jira users, do we still need to validate this requirement? I believe it is a default functionality inherent to Jira, and therefore might not require separate validation. Could you clarify this for me?
- I want to confirm: in my understanding, applications that involve automation are generally considered high-risk because automation processes have the potential to perform incorrect actions. Therefore, it's necessary to conduct frequent checks and validations. Am I correct in thinking this?
I would like to hear your thoughts and guidance please.