ChecklistImplementation

User acceptance testing checklist for ERP, CRM and platform rollouts

User acceptance testing is where the business, not the project team, decides whether a new system is fit to run its work. This checklist covers what must be true before testing starts, building scenarios from process maps, sourcing realistic and safe test data, testing with real role profiles, handling defects, accepting AI-enabled features and what formal sign-off should contain.

Reviewed 5 min read

On this page
  1. What UAT proves compared with system and integration testing
  2. Entry criteria before UAT starts
  3. Scope: scenarios built from process maps, not screens
  4. Test data that is realistic, migrated and masked
  5. Roles, access and segregation of duties in UAT
  6. Defect severity and triage definitions for UAT
  7. Accepting AI-enabled features with evaluation sets
  8. UAT exit criteria and formal business sign-off
  9. Hypothetical example: a UAT plan for a CRM replacement
  10. Questions and answers
  11. Sources

What UAT proves compared with system and integration testing

Quality engineering, one of ColdAI's implementation offerings, spans test automation, performance and security testing and quality governance1. UAT is the level the business owns, and it answers a different question from the levels before it.

QuestionSystem testingIntegration testingUser acceptance testing
Who runs itProject testers and developers.Project testers with interface owners.Business users who will do the work, supported by testers.
What it provesEach function behaves as specified.Data moves correctly between systems and errors are handled.The business can run its processes end to end.
Test cases come fromFunctional specifications and user stories.Interface specifications and data contracts.Process maps, business rules and recent real cases.
Who passes itThe test lead.The test lead with interface owners.The accountable business owner.

Entry criteria before UAT starts

0 of 6 checked

Scope: scenarios built from process maps, not screens

Screen-by-screen scripts prove that fields accept input. Business scenarios prove that an order becomes cash or a claim becomes a payment.

0 of 5 checked

Test data that is realistic, migrated and masked

0 of 5 checked

Roles, access and segregation of duties in UAT

0 of 5 checked

Defect severity and triage definitions for UAT

Agree these words before testing, review new defects daily, and rerun an agreed regression set after each round of fixes so a fix does not break something that already passed.

Critical
A core business process cannot be completed and there is no workaround.
High
A process can be completed only with a workaround that is costly or risky at production volume.
Medium
A defect with a simple workaround or a contained effect on one variant.
Low
Cosmetic or minor issues that do not affect results.
Change request
Something users want that was never in scope; it goes to the backlog rather than the defect queue.

Accepting AI-enabled features with evaluation sets

Document extraction, summarization or classification features give variable outputs, so a single expected result per test case does not work.

0 of 5 checked

UAT exit criteria and formal business sign-off

0 of 5 checked

Hypothetical example: a UAT plan for a CRM replacement

Questions and answers

Who should write UAT scenarios?

Business process owners, helped by testers who know how to structure them. Owners know the variants, exceptions and period-end steps that matter; testers make scenarios repeatable and traceable to requirements. Scripts written only by the project team tend to test what was built rather than what the business needs.

How long should a UAT cycle run?

Long enough to run every scenario, fix the defects found and rerun regression, usually in at least two cycles. Duration depends on scenario count and tester availability more than system size. Protect testers' time: UAT squeezed into spare hours produces shallow testing and late sign-off.

Can UAT be automated?

Partly. Regression of stable scenarios can be automated, which frees business testers for judgment-heavy work such as exceptions, outputs and usability. The acceptance decision itself cannot be automated, because it is a business owner stating that the system is fit for their process.

Is UAT still needed when delivery runs in sprints with regular demos?

Yes. ColdAI's iterative delivery ends each two-week sprint with working software and a stakeholder demo1, which surfaces problems early. Demos show features in isolation, though; UAT confirms complete processes on migrated data with real roles before go-live.

Sources

  1. Implementation: approach and quality engineering offering — ColdAI
  2. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  3. Sarbanes-Oxley Act of 2002 (Public Law 107-204) — U.S. Government Publishing Office · checked 10 October 2026
  4. Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  5. AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026

More in Implementation

Back to Implementation

Next step

Get a second opinion on your UAT plan before testing starts

Send the scope, scenario list and planned dates. We will point out missing process variants, data or role coverage, and suggest exit criteria your business owners can sign against.

Review my UAT plan