info@trustbridge-compliance.com
Home / Consulting / Assessments / CSA Maturity Index
The CSA Maturity Index

Decided to move to CSA? Start by finding your starting point.

Twenty questions, about six minutes, one per screen. You will see where you stand today, the tier you are moving from, and the first moves on your path, so the plan you take to your leadership is grounded in your reality. Your result appears on screen the moment you finish.

Prefer a plain single-page version, or did the interactive check not start above? Open it here.

Answer what you can, add your details at the end, and your scored read arrives by email.

1. What share of your GxP systems are validated under a risk-based CSA approach today?
2. Is there a leadership mandate and roadmap to move from CSV to CSA?
3. Across how many sites is the CSA approach applied consistently?
4. Have you retired documentation-heavy practices where risk does not warrant them?
5. Do you assess risk at the function or feature level, not just the system level?
6. Does validation effort scale to function risk (heavier for high-risk, lighter for low)?
7. Is intended use the starting point for each system's assurance?
8. Are your teams trained and confident in risk-based critical thinking, rather than following checklists?
9. Are assurance decisions documented with rationale (why this level of testing)?
10. Do you use unscripted or exploratory testing where it is appropriate?
11. Do you leverage supplier or vendor testing evidence to avoid duplicating effort?
12. Is digital evidence (logs, automated results, screenshots) accepted in place of manual scripts where justified?
13. Do you assess suppliers and rely on their quality proportionate to risk?
14. Are quality agreements and shared-responsibility models defined, including for SaaS and cloud?
15. Is documentation sized to risk, rather than produced uniformly for every system?
16. Can you find and present assurance evidence quickly, organised and traceable?
17. Is there one governance model or standard applied across sites, not local variants?
18. Is change managed with risk-based revalidation triggers?
19. Is your CSA approach built to extend to AI-enabled systems?
20. Could your CSA evidence withstand an inspection today without a scramble?