ChecklistImplementation
User acceptance testing checklist for ERP, CRM and platform rollouts
User acceptance testing is where the business, not the project team, decides whether a new system is fit to run its work. This checklist covers what must be true before testing starts, building scenarios from process maps, sourcing realistic and safe test data, testing with real role profiles, handling defects, accepting AI-enabled features and what formal sign-off should contain.
On this page
- What UAT proves compared with system and integration testing
- Entry criteria before UAT starts
- Scope: scenarios built from process maps, not screens
- Test data that is realistic, migrated and masked
- Roles, access and segregation of duties in UAT
- Defect severity and triage definitions for UAT
- Accepting AI-enabled features with evaluation sets
- UAT exit criteria and formal business sign-off
- Hypothetical example: a UAT plan for a CRM replacement
- Questions and answers
- Sources
What UAT proves compared with system and integration testing
Quality engineering, one of ColdAI's implementation offerings, spans test automation, performance and security testing and quality governance1. UAT is the level the business owns, and it answers a different question from the levels before it.
| Question | System testing | Integration testing | User acceptance testing |
|---|---|---|---|
| Who runs it | Project testers and developers. | Project testers with interface owners. | Business users who will do the work, supported by testers. |
| What it proves | Each function behaves as specified. | Data moves correctly between systems and errors are handled. | The business can run its processes end to end. |
| Test cases come from | Functional specifications and user stories. | Interface specifications and data contracts. | Process maps, business rules and recent real cases. |
| Who passes it | The test lead. | The test lead with interface owners. | The accountable business owner. |
Entry criteria before UAT starts
Scope: scenarios built from process maps, not screens
Screen-by-screen scripts prove that fields accept input. Business scenarios prove that an order becomes cash or a claim becomes a payment.
Test data that is realistic, migrated and masked
Roles, access and segregation of duties in UAT
Defect severity and triage definitions for UAT
Agree these words before testing, review new defects daily, and rerun an agreed regression set after each round of fixes so a fix does not break something that already passed.
- Critical
- A core business process cannot be completed and there is no workaround.
- High
- A process can be completed only with a workaround that is costly or risky at production volume.
- Medium
- A defect with a simple workaround or a contained effect on one variant.
- Low
- Cosmetic or minor issues that do not affect results.
- Change request
- Something users want that was never in scope; it goes to the backlog rather than the defect queue.
Accepting AI-enabled features with evaluation sets
Document extraction, summarization or classification features give variable outputs, so a single expected result per test case does not work.
UAT exit criteria and formal business sign-off
Hypothetical example: a UAT plan for a CRM replacement
Questions and answers
Who should write UAT scenarios?
Business process owners, helped by testers who know how to structure them. Owners know the variants, exceptions and period-end steps that matter; testers make scenarios repeatable and traceable to requirements. Scripts written only by the project team tend to test what was built rather than what the business needs.
How long should a UAT cycle run?
Long enough to run every scenario, fix the defects found and rerun regression, usually in at least two cycles. Duration depends on scenario count and tester availability more than system size. Protect testers' time: UAT squeezed into spare hours produces shallow testing and late sign-off.
Can UAT be automated?
Partly. Regression of stable scenarios can be automated, which frees business testers for judgment-heavy work such as exceptions, outputs and usability. The acceptance decision itself cannot be automated, because it is a business owner stating that the system is fit for their process.
Is UAT still needed when delivery runs in sprints with regular demos?
Yes. ColdAI's iterative delivery ends each two-week sprint with working software and a stakeholder demo1, which surfaces problems early. Demos show features in isolation, though; UAT confirms complete processes on migrated data with real roles before go-live.
Sources
- Implementation: approach and quality engineering offering — ColdAI
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Sarbanes-Oxley Act of 2002 (Public Law 107-204) — U.S. Government Publishing Office · checked 10 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026