GxP validation of Dynamics 365 Finance and Supply Chain for life sciences

By Emil Björk · Microsoft business apps consultant, Gothenburg

How to validate Dynamics 365 Finance and Supply Chain Management in a GxP environment — what FDA 21 CFR Part 11 actually asks of the system, the in-product electronic signature and audit features, the risk-based approach that survives monthly service updates, and where validation accelerators and serialisation ISVs fit.

Updated 2026-09-02

A pharmaceutical, medical-device, or biotech company running Dynamics 365 Finance and Supply Chain Management for batch manufacturing, quality, or distribution is running a GxP system, and regulators expect it to be validated: documented evidence that it does what it is supposed to do, with controls over who can change what. Microsoft does not deliver a validated system; it delivers a platform with the controls needed to build one. The shape of the work is different from validating an on-premises ERP a decade ago, because the platform changes every month. This guide covers what the product provides, what the customer has to do, and the approach that makes continuous updates survivable. For the industry context see Dynamics 365 for healthcare.

What Part 11 actually demands

FDA 21 CFR Part 11 and the equivalent EU Annex 11 are shorter than their reputation. Applied to an ERP they require: secure, computer-generated, time-stamped audit trails for creation, modification, and deletion of GxP records; system access limited to authorised individuals; electronic signatures that are unique, verifiable, and bound to the record with the signer's name, date, and meaning; and validation of the system for its intended use. Everything else is procedure — training, SOPs, change control — that the company owns regardless of the software.

What is in the product

Electronic signatures. Finance and Supply Chain Management has a first-party electronic signature feature: specific tables and fields can be configured to require a signature on change, with reason codes, a re-authentication prompt, and a signature log. It ships with a set of signable operations — quality orders, batch attributes, BOM approvals, and others — and can be extended to custom fields. This is the Part 11 signature mechanism, and it is adequate for most use cases without an ISV.

Audit trail. The database log records inserts, updates, and deletes on selected tables and fields with user and timestamp. It must be enabled per table deliberately — turning it on for everything cripples performance — so part of validation is deciding which records are GxP records and logging exactly those. Configuration changes are separately tracked through the feature-management and configuration-history mechanisms, and Lifecycle Services or the Power Platform admin centre records environment operations.

Security. Role-based security with duties and privileges, segregation-of-duties rules that flag conflicting role assignments, and Entra ID for identity, multi-factor authentication, and conditional access. Access reviews are an Entra feature that GxP auditors increasingly expect.

Quality and traceability. Quality orders, nonconformance, batch and serial tracking with expiry and shelf-life, batch attributes, and item tracing that answers "where did this batch go" for a recall. The quality management and tracking dimensions guides cover the mechanics.

Platform assurance. Microsoft publishes SOC and ISO reports, a Part 11 position, and infrastructure qualification evidence through the Service Trust Portal. That is the vendor-side documentation a supplier assessment draws on. It does not qualify the customer's configuration.

What is not in the product

Electronic batch records with step-by-step execution and signatures at each step are MES territory, not ERP, and Supply Chain Management integrates to an MES rather than replacing one — the shop floor control guide covers the boundary. Serialisation and aggregation for DSCSA in the US or the EU Falsified Medicines Directive need a serialisation platform; there are established ISVs. Laboratory information management is LIMS, integrated to quality orders. Deviation, CAPA, and document management usually live in a QMS, though some companies run CAPA as cases in Dynamics 365 Customer Service.

Business Central has none of the electronic signature or database-log features natively. Life-sciences companies on BC rely on ISVs for signatures and audit trails; several exist, and their validation posture should be assessed as carefully as BC's own.

Validating a system that updates monthly

The One Version model means Finance and Supply Chain Management receives service updates on a fixed cadence, with a limited ability to pause and no ability to stay on an old version indefinitely. A validation approach built on requalifying the whole system after every update is not sustainable. The approach that regulators have accepted and that works in practice:

  • Risk-based validation in the spirit of GAMP 5 second edition and FDA's computer software assurance guidance: classify functions by GxP impact, and focus scripted testing on high-impact ones. Standard, unconfigured functionality gets less testing than customisations.
  • A validated core with a defined update procedure. The initial validation covers installation qualification (environment and configuration, largely Microsoft's evidence plus the customer's configuration record), operational qualification (the configured processes), and performance qualification (in the business context). Each service update then goes through impact assessment against Microsoft's release notes, regression testing of the high-impact scenarios, and a signed update record.
  • Automated regression. The Regression Suite Automation Tool records business processes from Task Recorder and replays them; the Lifecycle Services guide describes it. A library of RSAT scripts for the GxP-critical processes turns each monthly update into a repeatable, evidenced test run instead of a manual re-execution.
  • Configuration and customisation control. Every X++ extension and every configuration change in production goes through change control, with the database log and the release pipeline as the evidence.

Partners sell validation accelerators — pre-written requirement specifications, test scripts, and traceability matrices for the standard modules. They shorten the first validation noticeably and are worth buying if they match the implementation's scope; they still need adapting, and the update procedure remains the customer's.

The organisational part

Validation fails in life-sciences ERP projects for organisational reasons more than technical ones: quality assurance is engaged after configuration is finished, the partner's methodology has no place for a validation plan, or the business treats service updates as IT's problem. Put quality assurance on the steering committee, include the validation plan and traceability matrix in the statement of work, and staff a permanent role that owns the update assessment. The technology is ready; the process has to be.

Further reading

Related guides

Spot something wrong or want a topic covered? Send a correction or a topic request — both are welcome.