This is a ready-to-use decision matrix for the term pairs and clusters that get mixed up most often in GxP, CSV, and data integrity work: in meetings, in written investigations, and in interviews. When two people are talking past each other because they are using the same word for two different things, or two different words for the same thing, this is what you pull up to settle it and move on. Replace the <<FILL: ...>> placeholders with your own specifics. A filled specimen follows. This is general guidance to adapt, not legal or regulatory advice; verify each definition against the current source before you rely on it. It pairs with The GxP, CSV, and Data Integrity Glossary, which carries the full definitions, regulatory basis, and worked examples behind every row.
Header
| Field | Entry |
|---|---|
| Matrix owner | <<FILL>> |
| Site(s) applicable | <<FILL>> |
| Version | <<FILL>> |
| Last verified date | <<FILL>> |
1. How to use this matrix
Find the row closest to your confusion, read the one-line meaning of each option, then answer the distinguishing question. The question is written to be answerable from the facts in front of you, not from memory of a definition. Write the term you land on, and the row number you used, directly into the record; it gives a reviewer a fast way to check your reasoning instead of just your conclusion.
2. The matrix
| # | Confused pair or cluster | Option A | Option B (and C if applicable) | The distinguishing question | Related term |
|---|---|---|---|---|---|
| 1 | GLP vs GMP (QC testing) | GLP: 21 CFR Part 58, nonclinical safety studies supporting a regulatory submission | GMP: 21 CFR 210/211, commercial and clinical manufacturing and its QC testing | Is this a nonclinical toxicology or safety study, or is it a manufacturing or QC activity? | GLP, GMP |
| 2 | Qualification vs Validation vs Verification | Qualification: documented evidence equipment or a system is installed and operating correctly (DQ/IQ/OQ/PQ) | Validation: documented evidence a process or system consistently delivers its intended result across its full range; Verification: confirms an already-established method or system works in your hands | Am I proving something works here for the first time, proving equipment is installed and operating right, or confirming something already proven elsewhere still holds here? | Qualification, Validation, Verification |
| 3 | CSV vs CSA | CSV: the overall discipline, documented evidence a computerized system is fit for use | CSA: FDA’s guidance, formally scoped to 21 CFR 820.70(i), on how much and what kind of testing rigor a given function needs | Am I asking what needs to be validated at all (CSV, always applies), or how deep the testing should go for a specific function (CSA’s question)? | CSV, CSA |
| 4 | True copy vs Certified copy | True copy: US/Part 11 vocabulary for a copy that preserves meaning and metadata | Certified copy: UK/EU vocabulary for the same idea, plus a signed confirmation by a person with the authority to make it | Which region’s guidance governs this record, and has anyone signed to confirm the copy is accurate and complete? | True copy, Certified copy |
| 5 | Static vs Dynamic record | Static: fixed once captured, like a printout or a flat PDF | Dynamic: can still be reprocessed, recalculated, or filtered after capture | If I gave this record to someone else right now, could they still change how it is displayed, integrated, or calculated? | Static vs Dynamic records |
| 6 | Data Integrity vs Data Quality vs Data Governance | Data Integrity: is the record complete, attributable, and unaltered across its lifecycle | Data Quality: is the underlying value correct, precise, and fit for its use; Data Governance: who owns, decides, and keeps both sets of controls current | Is the record trustworthy, is the number itself right, or is the real problem that no one is accountable for either? | Data governance, Data quality |
| 7 | Deviation vs OOS vs OOT vs Nonconformance | Deviation: a departure from an approved procedure, specification, or standard | OOS: a lab result outside an established acceptance criterion; OOT: a result within spec but inconsistent with the expected pattern; Nonconformance: a broader term, often site-specific vocabulary for the same idea as deviation | Is this a missed or altered procedural step, a lab result that failed its acceptance criterion, or a result that passed but does not fit the pattern? | Deviation, OOS / OOT |
| 8 | Correction vs Corrective Action vs Preventive Action | Correction: fixes the immediate symptom right now | Corrective action: fixes the root cause of a problem that already happened; Preventive action: stops a potential problem before it happens at all | Am I fixing what is in front of me right now, fixing why it happened so it will not recur, or stopping something that has not happened yet? | CAPA |
| 9 | Form 483 vs Untitled Letter vs Warning Letter vs Import Alert vs Consent Decree | An ascending escalation ladder: 483 lists inspectional observations; Untitled Letter is a lower-severity advisory; Warning Letter is formal notice of significant violations | Import Alert detains product at the US border without physical examination; Consent Decree is a court-entered, binding injunction | Is this the end-of-inspection observation list, a lower-severity advisory, a formal significant-violation notice, a border detention mechanism, or a court-ordered injunction? | Form 483 / Warning Letter, Untitled Letter, Import Alert, Consent Decree |
| 10 | Audit vs Inspection vs Assessment vs Management Review | Audit: your own or a supplier’s structured, planned examination against a defined standard | Inspection: a regulatory authority’s examination, carried out under statutory authority; Assessment: a broader, sometimes less formal evaluation such as a gap or risk assessment; Management review: leadership’s periodic look at overall QMS performance metrics | Who is doing the looking, under what authority, and is it examining one system or the whole quality system’s performance? | Internal audit program, Management review |
| 11 | Change control vs Configuration management | Change control: the formal approval process that happens before a change is made | Configuration management: the ongoing, current record of exactly what the system’s baseline looks like right now | Am I asking for permission to change something, or am I asking what the system currently looks like? | Change control, Configuration management |
| 12 | Periodic review vs Requalification vs Revalidation | Periodic review: a scheduled check confirming a system is still validated and under control | Requalification: repeating qualification activities, often after a defined trigger such as time, a change, or an excursion; Revalidation: repeating validation activities at the process or method level | Am I doing a scheduled health check, redoing equipment qualification after a trigger, or redoing process or method validation? | Periodic review |
| 13 | GAMP Category 3 vs 4 vs 5 | Category 3: off-the-shelf software used as supplied, with no GxP-specific configuration | Category 4: a configured product, such as a LIMS or MES, with site-specific configuration; Category 5: custom-coded software, or bespoke code embedded within a product | Did we use the software exactly as shipped, configure it for our process, or have code written specifically for us? | GAMP software categories |
| 14 | PQS vs QMS vs QMSR | PQS: ICH Q10’s name for the pharmaceutical quality system covering the full product lifecycle | QMS: the generic organizational term, or the specific software that runs deviations, CAPAs, and change controls; QMSR: the FDA device regulation, 21 CFR 820 as amended, anchoring device quality systems to ISO 13485 | Am I talking about the drug-lifecycle quality framework, the general concept or the software tool, or the device-specific regulation? | QMS, PQS, QMSR |
| 15 | PCCP vs standard change control (for an AI/ML system) | PCCP: a pre-agreed plan covering specific, anticipated categories of model change, such as periodic retraining, each with a predefined validation approach | Standard change control: the general assess, approve, test, and document process for a change that was not pre-specified | Was this exact type of change already described and pre-approved in the PCCP, or is it new enough that it needs the general change control process from scratch? | PCCP, Change control |
3. References
Term-level definitions, the regulatory basis for each, and worked examples: The GxP, CSV, and Data Integrity Glossary. Underlying regulations and standards referenced across these rows: 21 CFR Parts 11, 58, 210, 211, and 820 (as amended by QMSR); EudraLex Volume 4 and Annexes 11 and 16; ICH Q9(R1) and Q10; GAMP 5; MHRA GxP Data Integrity Guidance and Definitions; PIC/S PI 041.
Confirm the current version, title, and clause numbers of any cited source before you rely on it or cite it to an inspector.
Filled specimen
Three real resolutions from one site, logged the way an analyst or investigator would use the matrix in practice.
| Scenario | Row used | Distinguishing answer | Term applied |
|---|---|---|---|
| An HPLC assay result fails its acceptance criterion during routine release testing | Row 7 | The result failed an established acceptance criterion; no procedural step was missed or altered | OOS, per the two-phase OOS investigation process |
| A new validation engineer is asked to “qualify” a LIMS report that has already been validated at a sister site and is being reused as-is | Row 2 | Something already proven elsewhere is being confirmed to still hold here, not proven for the first time | Verification, scoped to confirming equivalence at this site |
| A team debates whether a CDS re-integration audit trail gap is a “data integrity issue” or a “data quality issue” | Row 6 | The question is whether the change was attributable and explained (it was not); the underlying chromatographic result itself was not shown to be numerically wrong | Data integrity gap, investigated as such, not filed as a data quality concern |
In each case the person used the distinguishing question to reach a defensible term choice in under a minute, and wrote the row number into the record so a reviewer could check the reasoning rather than just the conclusion.
How to adapt this matrix
- Set the owner, site, and verification date in the header.
- Add rows for the specific confusions that come up at your site; a clinical-heavy group may want rows distinguishing SDV from source data review, or protocol deviation from GCP nonconformance.
- Keep every distinguishing question answerable from facts in front of the reader, not from a memorized definition; if a row’s question requires looking something up, rewrite it.
- Point users to The GxP, CSV, and Data Integrity Glossary for the full reasoning behind any row before they cite it externally.
- Re-verify the matrix whenever a cited regulation or guidance is revised, the same way you would re-verify the acronym quick-reference card.