In regulated environments, ‘we have backups’ is not evidence. Inspectors look for proof that restores work, that scope is appropriate, and that the organisation can recover critical records when it matters.
Adopt a risk-based approach that covers regulated records, configuration and critical supporting components, without creating disproportionate testing overhead.
These items form the core of a defensible backup and restore evidence set for GxP systems including those hosted by SaaS vendors.
A structured review of your backup and restore controls, evidence and supplier governance, with a clear remediation path.