QMS Nordic
PrivacyTermsSecuritySub-processorsAI ActValidation

← Software validation pack

Test Protocol and Results — QMS Nordic

Template — QMS Nordic T4. Scripts are pre-written; you execute them.

Why you test at all when we have tested already. Our evidence shows the platform behaves as specified. It cannot show that your configuration, your roles and your processes produce the result you need — and that is precisely the gap an auditor probes. "We read the vendor's package" is the answer that generates the finding.

Run only what your risk assessment says to run. T3 decided the depth; this executes it. A protocol that tests everything regardless of risk is not more rigorous, it is undirected — and it invites the question of why you tested the colour of a button but not who can delete a record.

Effort: 1–2 days for a High-risk categorisation. Less if you use fewer modules.

Test Protocol and Results — QMS Nordic
Document[DOC-XXX] Test protocol and results — QMS Nordic
SoftwareQMS Nordic v1.5.0
Environment[your tenant URL]
Tester[name]
Dates[from] – [to]

1. Before you start

  • ☐You have a test user at each role level you use
  • ☐You have a second test user — several tests need two people
  • ☐You are testing in your own tenant, on the configuration you will use
  • ☐You know your risk ratings from T3 — they decide which sections to run

Test in your real tenant, not a sandbox, unless you have a genuine reason not to. The point is to validate the configuration you will actually use. Create test records, prefix them clearly (VALIDATION-), and remove them afterwards — recording that you did.


2. Core tests — run these if your risk assessment rated anything High

2.1 Document control

2.1 Document control
#StepsExpectedResultEvidence
T-DOC-01Create a document, take it through your approval route to effectiveOnly the approved version shows as effective; the route matches your process☐P ☐F 
T-DOC-02Edit an effective documentA new version is created; the previous version remains retrievable; status returns for re-approval☐P ☐F 
T-DOC-03Retrieve a superseded versionPrior content is readable and clearly marked as not current☐P ☐F 
T-DOC-04Attempt to approve a document as its authorBlocked, if your process requires separation of duties☐P ☐F ☐N/A 

2.2 Audit trail — the one to do properly

2.2 Audit trail — the one to do properly
#StepsExpectedResultEvidence
T-AUD-01Change a record. View its audit trailEntry shows who, when, what changed, and the previous value☐P ☐F 
T-AUD-02Attempt to edit or delete an audit entry through the interfaceNo means exists to do so☐P ☐F 
T-AUD-03Ask QMS Nordic to demonstrate that a direct database alteration of an audit record is detectableDemonstrated; you record what you were shown and by whom☐P ☐F 
T-AUD-04Export an audit trailReadable outside the system☐P ☐F 

T-AUD-03 needs us. Ask — it is a reasonable request and we will show you. "We asked the vendor to demonstrate audit-trail tamper detection and they did, on [date]" is a strong line. If a vendor cannot demonstrate it, that is worth knowing before you rely on the records.

2.3 Access and separation

2.3 Access and separation
#StepsExpectedResultEvidence
T-ACC-01Log in as each role you use; attempt an action outside that rolePermitted actions succeed; others are refused☐P ☐F 
T-ACC-02Confirm no records from another organisation are visible anywhereNone☐P ☐F 
T-ACC-03Remove a test user via your leaver process, then attempt to log in as themAccess refused☐P ☐F 

T-ACC-03 tests you, not us. It is the most commonly found gap under this clause, and the only test here that a vendor package can never cover.

2.4 Electronic signature (N/A if unused)

2.4 Electronic signature (N/A if unused)
#StepsExpectedResultEvidence
T-SIG-01Sign a documentRe-authentication is required at the moment of signing☐P ☐F ☐N/A 
T-SIG-02Inspect the applied signatureRecords signer, date, time and meaning☐P ☐F ☐N/A 
T-SIG-03Modify a signed documentA new version is required and re-approval is triggered☐P ☐F ☐N/A 

2.5 AI drafting (N/A if unused)

2.5 AI drafting (N/A if unused)
#StepsExpectedResultEvidence
T-AI-01Generate a draft; inspect its provenanceIdentified as AI-generated, with model and generation recorded☐P ☐F ☐N/A 
T-AI-02Attempt to make an AI draft effective without human approvalNot possible in your process — if it is, record it as a finding against yourself☐P ☐F ☐N/A 
T-AI-03Read a generated document to its endIt ends properly, not mid-sentence☐P ☐F ☐N/A 

T-AI-02 is a test of your process, not the software. If a draft can reach effective status without a person approving it, the software will let you — and an auditor will find it.

2.6 Retention and export

2.6 Retention and export
#StepsExpectedResultEvidence
T-RET-01Export a full record setComplete and readable without the platform☐P ☐F 
T-RET-02Confirm export covers everything you must retainNothing required is missing☐P ☐F 

3. Your own workflows

The tests above cover platform behaviour. These cover your processes, and they are the ones an auditor will care about most — because they are the ones nobody else could have written for you.

3. Your own workflows
#WorkflowStepsExpectedResultEvidence
T-OWN-01[e.g. Raise a CAPA from a complaint and close it]  ☐P ☐F 
T-OWN-02   ☐P ☐F 
T-OWN-03   ☐P ☐F 

4. Deviations

Record every failure. A failed test with a documented resolution is evidence of a working process; an absent failure record in a system that clearly had problems reads as an incomplete one.

4. Deviations
#TestWhat happenedAssessmentResolutionClosed
D-01    ☐

5. Summary

5. Summary
Tests planned[—]
Passed[—]
Failed[—]
N/A (function not used)[—]
Deviations open[—]
Test records removed afterwards☐
5. Summary
RoleNameSignatureDate
Tested by   
Reviewed by   

QMSN-T4 · v1.5.0 · pack rev. J (2026-09-07)
Published at qmsnordic.com/legal/validation/t4-test-protocol. Cite the version above in your validation record — a pack is evidence, and evidence has to stay retrievable at the version you validated against.

© 2026 Aitech International ApS · Denmark · All rights reserved.QMS Nordic™ is owned, developed, and copyright-protected by Aitech International ApS.
PrivacyTermsSecuritySub-processorsAI ActValidationHome