Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs
SAS validation, 21 CFR Part 11, and GAMP 5 compliance services for clinical programming

SAS Validation, 21 CFR Part 11 & GAMP 5 Compliance

GxP validation for SAS 9.4, SAS LSAF, and SAS Viya clinical programming environments — risk-based validation, controlled SDLC, ALCOA+ data integrity, and audit-ready documentation for FDA, EMA, and PMDA inspections.

Our SAS Validation Services

We validate SAS environments end-to-end — from URS through Validation Summary Report — with risk-based scoping, controlled SDLC for customer-developed macros, and inspection-ready documentation aligned to FDA, EMA, MHRA, and PMDA expectations.

Validation
Environment Validation
Full GAMP 5 validation of SAS 9.4, LSAF, or Viya — URS, configuration spec, FMEA risk assessment, IQ/OQ/PQ, traceability matrix, and Validation Summary Report ready for inspection.
Plan validation
Governance
Controlled SDLC
Design and implement the controlled lifecycle for customer-developed SAS macros, study programs, and the regulatory macro library — peer review, validation, change control, and periodic review SOPs.
Discuss SDLC
Operations
Periodic Review & Audit Support
Ongoing periodic review of validated SAS environments, change-control execution, regression testing across SAS releases, and inspection support during FDA BIMO and EMA GCP inspections.
Managed services

Risk-Based Validation, Not Checklist Theater

We apply the ISPE GAMP 5 Second Edition risk-based principles and the FDA Computer Software Assurance (CSA) framework to focus validation effort on the controls that actually matter for patient safety and data integrity. SAS 9.4 base procedures get supplier-IQ-driven validation; customer-developed macros that produce SDTM/ADaM/TLF outputs get full lifecycle controls. The footprint is proportionate to risk — not a uniform layer of paperwork across every script.

Risk-based GAMP 5 validation strategy for SAS clinical programming environments

One Package for FDA, EMA, and PMDA

Sponsors filing in multiple jurisdictions need validation that satisfies 21 CFR Part 11, EU Annex 11, the EMA Computerised Systems Guideline, the WHO Annex 5, and PMDA expectations. We build a unified validation package that explicitly maps controls to every regulatory framework in scope — eliminating duplicate validation work across programs.

Unified multi-jurisdiction validation package for FDA, EMA, MHRA, and PMDA SAS submissions

Inspection-Ready by Design

FDA BIMO inspections and EMA GCP inspections request specific validation evidence — controlled SDLC for submission programs, audit trails for critical macros, data transfer specifications, and reconciliation evidence. We build packages that present this evidence cleanly, indexed for the predictable inspector requests, and supported by SOPs that QA and biostatistics teams can demonstrate live.

Inspection-ready validation evidence presentation for FDA BIMO and EMA GCP inspections

What We Deliver for SAS Compliance

A complete validation lifecycle for SAS environments and customer-developed program estates — risk-based, multi-jurisdiction, and integrated with the sponsor's broader CSV program.

Full Validation Package

URS, configuration specification, FMEA risk assessment, validation plan, IQ/OQ/PQ protocols and reports, traceability matrix, and Validation Summary Report. Aligned to GAMP 5 and FDA software validation principles.

Plan validation

Controlled SDLC Design

Design and implement the controlled lifecycle for customer-developed SAS macros and study programs — draft, peer review, validation, release, retirement — with documented entry/exit criteria and reviewer responsibilities.

Discuss SDLC

ALCOA+ Data Integrity

Embed Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available controls into the SAS data flow — including data transfer specifications and EDC-to-SAS reconciliation reports.

Data integrity

Macro Library Governance

Build a tiered governance model for sponsor SAS macro libraries — core regulatory macros, program-specific macros, and exploratory macros — with formal validation and change control proportionate to each tier.

Library governance

Periodic Review Execution

Ongoing periodic review of the validated SAS environment, audit trail review, configuration baseline verification, incident and change-control review, and continued-fitness conclusion documented for the regulator.

Managed services

Inspection & Audit Support

Live support during FDA BIMO inspections, EMA GCP inspections, sponsor audits of CRO SAS environments, and Notified Body audits — including pre-inspection rehearsal and inspector-question response coaching.

Inspection support

Why IntuitionLabs for SAS Validation

Generic CSV firms validate SAS as if it were any other system. We bring specific clinical programming expertise — CDISC SDTM/ADaM, biostatistics workflow, validated macro libraries — alongside GAMP 5 and Part 11 expertise. The result is validation that protects regulatory continuity without paralyzing the programming team.

Clinical Programming Fluency

We speak SAS, CDISC, and SAP. Our validation packages reflect how clinical programmers actually work, not a generic IT validation template.

Multi-Jurisdiction Coverage

21 CFR Part 11, EU Annex 11, WHO Annex 5, EMA Computerised Systems Guideline, and PMDA expectations — one unified package, no duplicate work.

Inspection-Ready Posture

We have walked through BIMO and GCP inspections. Our packages are organized for the questions inspectors actually ask.

Regulatory Frameworks We Cover

📜

21 CFR Part 11

Electronic records and electronic signatures applied to SAS program releases, audit trails on the controlled program repository, and the controlled program lifecycle for submission-grade work.

🇪🇺

EU Annex 11

Risk-based validation, controlled data lifecycle, periodic review, and supplier qualification for SAS-hosted and customer-managed environments serving EMA submissions.

📐

GAMP 5 (2nd Edition)

Risk-based classification and validation for the SAS engine (Category 3), configured tenants (Category 4), and customer-developed macros (Category 5), with iterative delivery patterns where appropriate.

🔐

MHRA & PIC/S Data Integrity

ALCOA+ data integrity controls embedded in the SAS pipeline — data transfer specifications, reconciliation, audit trails, and metadata describing every derivation.

🧪

ICH E6 / GCP & E9 Statistics

Validation that supports ICH E6(R3) Good Clinical Practice obligations on data management and ICH E9 statistical principles, including ICH E9(R1) on Estimands.

📊

FDA Study Data Standards

Conformance to the FDA Study Data Technical Conformance Guide, accepted formats (SAS Transport XPT), and the eCTD Module 5 submission expectations for SDTM, ADaM, and Define-XML.

Frequently Asked Questions

Under the ISPE GAMP 5 Second Edition framework, SAS itself — the Base SAS engine and STAT procedures — is generally classified as a GAMP Category 3 (non-configured) product. The sponsor's configured deployment (SAS LSAF tenant configuration, controlled program libraries, customer-developed macros) is Category 4 (configured) or Category 5 (custom) depending on the depth of in-house development. The validation strategy follows this classification: rely on supplier IQ/OQ for the underlying SAS engine, perform configuration verification on the controlled environment, and apply full lifecycle controls to customer-developed macros that influence regulated outputs. The GAMP 5 guidance on agile and iterative delivery applies to the customer-developed layer.
A complete validation package for a SAS environment supporting clinical programming typically includes the User Requirements Specification (URS) defining the regulated functions; the Functional / Configuration Specification documenting the SAS LSAF or controlled SAS 9.4 / Viya configuration; an FMEA-based Risk Assessment identifying critical functions and required controls; the Validation Plan defining scope, deliverables, and acceptance criteria; IQ / OQ / PQ protocols and reports verifying installation, operational, and performance qualification; a Requirements Traceability Matrix linking requirements to tests to evidence; SOPs covering the controlled SDLC for customer-developed SAS macros, change control, periodic review, and incident management; and a Validation Summary Report concluding the released state. All artifacts align to GAMP 5 and the FDA General Principles of Software Validation.
21 CFR Part 11 applies to electronic records and electronic signatures used to satisfy predicate rule requirements — which includes SAS programs producing the SDTM, ADaM, and TLF outputs that support an NDA, BLA, or MAA. Part 11 controls applied to the SAS environment cover: electronic signature on study program releases capturing printed name, date/time, and meaning of signature; immutable audit trails on the controlled program repository tracking every program change, who made it, and when; password and session policy enforcement; controlled program lifecycle (draft, peer reviewed, validated, locked, retired); and validated electronic copies of regulated records. SAS LSAF provides these technical controls natively; standalone SAS 9.4 deployments require careful environment design and supporting platform controls to achieve equivalence.
The EU Annex 11 (Computerised Systems) framework parallels 21 CFR Part 11 with some differences in emphasis — it requires risk-based validation, controlled data lifecycle, periodic review, and supplier qualification for hosted systems. For sponsors filing in both FDA and EMA jurisdictions, we build a unified validation package that explicitly maps requirements to both Part 11 and Annex 11 controls, plus the WHO Annex 5 on Computerised Systems and Electronic Data in Clinical Trials and the EMA Guideline on Computerised Systems and Electronic Data in Clinical Trials. The unified approach avoids duplicate validation work across regulatory programs.
A controlled SDLC for SAS programs typically follows a draft → peer review → validation → release → periodic review lifecycle, enforced either by SAS LSAF native workflows or by an external version control system (Git) wrapped in controlled processes. Each stage has defined entry and exit criteria, required reviewers, and documentation expectations. Programs influencing regulatory outputs (SDTM, ADaM, TLF programs) receive the most stringent treatment; exploratory or scratch programs operate with lighter controls. We define the per-study and per-macro classification in the validation plan, build the workflow into the environment, and train programmers and QC reviewers on the controlled lifecycle. The framework aligns to FDA software validation principles and GAMP 5 expectations for customer-developed software.
Data integrity in the clinical SAS pipeline must satisfy the MHRA GxP Data Integrity Guidance, FDA Data Integrity Guidance, and the PIC/S PI 041 Good Practices for Data Management and Integrity. The ALCOA+ principles — Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available — apply at every step. In practice: documented data transfer specifications when raw EDC data enters the SAS environment, with reconciliation reports comparing source extracts to loaded copies; immutable audit trails on every program execution recording inputs, program version, and outputs; metadata describing every derivation; and a release process that locks the SDTM/ADaM datasets and their producing programs at submission time. We design the controls into the environment from day one.
During an FDA Bioresearch Monitoring (BIMO) inspection or an EMA GCP inspection, inspectors typically request the validation summary report, the controlled SDLC for programs producing submission outputs, the audit trail for selected critical programs, the data transfer specifications between EDC and SAS, the reconciliation evidence between source and analysis datasets, and the change-control records for any program revisions during the trial. We prepare the validation package to be inspector-ready by design — well-organized, indexed, and supported by SOPs that the QA and biostatistics teams can demonstrate live. We have supported clients through BIMO and Notified Body inspections of validated SAS environments.
SAS Viya introduces several validation considerations that traditional SAS 9.4 does not. It is a microservices-based platform running on Kubernetes, which means infrastructure validation extends to the container orchestration layer (Kubernetes, Red Hat OpenShift) and the cloud control plane (AWS, Azure, GCP). It exposes REST APIs that can be orchestrated by external systems, requiring validation of those integration points. It supports Python and R as first-class languages, meaning the customer-developed code estate now spans multiple languages and the controlled SDLC must accommodate all of them. It releases more frequently than SAS 9.4 maintenance releases, requiring a periodic-release validation strategy with risk-based regression testing. We build Viya validation packages that explicitly cover Kubernetes-layer controls, REST API integration testing, and multi-language controlled SDLC for SAS plus Python plus R.
Sponsor SAS macro libraries — the validated reusable macros that encode statistical conventions, formatting standards, and CDISC handling — are critical regulatory infrastructure. We help organizations build a tiered governance model: core regulatory macros (highest control, formal validation, change control board sign-off); program-specific macros (study team controls, peer review); and exploratory macros (lightweight controls, clearly excluded from regulated use). The core library is treated as a Category 5 (custom) GAMP 5 product with its own validation lifecycle, periodic review, and regression test suite. Updates flow through formal change control with impact assessment on active studies. The pattern keeps the regulatory backbone stable while letting study teams move quickly on study-specific work.
Periodic review — required by both 21 CFR Part 11 and EU Annex 11 — is a documented re-evaluation of the validated state, typically on an annual cadence. For a SAS environment it covers: review of the configuration to confirm it matches the validated baseline; review of access provisioning and role assignments; review of the audit trail for anomalies; review of incidents and change controls executed since the prior review; review of the controlled macro library and any regression test failures; and a documented conclusion on continued fitness for regulated use, with any required corrective actions. We deliver periodic review as a managed service for clients who prefer to outsource the cadence rather than staff it internally. The framework aligns to FDA and EMA expectations on system lifecycle management.
Change control for SAS programs mid-study is one of the most scrutinized areas in inspections because program changes can affect the reproducibility of submitted analyses. Our standard approach: every program change carries a documented change request describing the reason and the regulatory impact assessment; changes to programs producing SDTM/ADaM datasets or TLFs require formal QA review; the prior validated version is retained for audit; the change is implemented in the controlled environment with peer review; the affected datasets and outputs are regenerated and re-QC'd; and the validation status of the affected study is updated. For changes that affect already-submitted analyses, the regulatory affairs team determines whether a formal supplement or amendment is required. The pattern keeps the regulatory chain of evidence intact even when programs evolve.
Validated SAS environments are one component of a sponsor's broader Computer System Validation (CSV) program. We integrate the SAS validation package into existing CSV governance — shared validation SOPs, shared change-control workflow, shared training records, and a unified inspection-readiness posture. Where appropriate we apply FDA Computer Software Assurance (CSA) risk-based principles to focus validation effort on the controls that matter most. The result is a validation footprint proportionate to risk, fully integrated with the sponsor's existing quality management system. See our full CSV practice.
Ready to Validate Your SAS Environment?
Ready to Validate Your SAS Environment? image

Ready to Validate Your SAS Environment?

Book a discovery session to scope a risk-based GAMP 5 validation package for your SAS 9.4, LSAF, or Viya environment — inspection-ready by design.

Book a Meeting

© 2026 IntuitionLabs. All rights reserved.