It sounds to me like the problem is with your process for validating(*1) NPS, not with the specific tool.
The fundamental issue (per the NC) is this:
- You have no documented evidence if the software needs to be validated (this is the risk assessment)
- Assuming it needed to be (re)validated, those records must have been lacking/missing
(*1) "Validating" NPS isn't
quite necessary... but you need to assess NPS. I'm simplifying a little because it sounds like you are in over your head, and such is not the time for nuance.