The ISPE guide providing a risk- and category-based framework for validating computerized systems, scaling effort to system complexity and novelty. The de facto global reference for CSV.
GAMP 5’s central idea is that validation effort should be proportionate to risk, complexity, and novelty — not applied uniformly to every system. It does this through software categories: Category 1 (infrastructure software), Category 3 (non-configured products used as supplied), Category 4 (configured products), and Category 5 (custom or bespoke code). A Category 3 system used out of the box needs far less specification and testing than a Category 5 application written for you.
The framework is built on a V-model that pairs each specification with its corresponding verification — user requirements verified by PQ, functional specification by OQ, design specification by IQ — held together by a risk assessment that decides how deeply to test each function. It also expects you to leverage supplier activity rather than duplicate it: if a reputable vendor has tested and documented something and you have assessed them, do not re-test it wholesale.
The 2nd edition (2022) modernised the guide considerably, aligning with the FDA’s Computer Software Assurance thinking (critical thinking over documentation volume), and adding guidance for Agile and iterative delivery, cloud and SaaS, software tools, and AI/ML. The direction of travel is unmistakable: less paper for its own sake, more evidence focused where patient safety and data integrity are actually at stake.
- —Software categories: 1 infrastructure · 3 non-configured · 4 configured · 5 custom — effort scales with category.
- —V-model pairs each specification with its verification (URS↔PQ, FS↔OQ, DS↔IQ).
- —Risk assessment decides test depth; not every function warrants the same rigour.
- —Leverage supplier documentation and assessment instead of duplicating vendor testing.
- —GAMP 5 2nd edition (2022) adds Agile, cloud/SaaS, AI/ML, and aligns with FDA CSA critical thinking.
- —A guide, not a regulation — but the de facto reference inspectors expect you to have applied.
ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd edition (2022). Applied against the binding requirements of 21 CFR Part 11 and EU GMP Annex 11; complementary to the FDA draft guidance on Computer Software Assurance (2022).
Frequently asked questions
What does GAMP 5 stand for?
GAMP 5 stands for Good Automated Manufacturing Practice (ISPE).
What is GAMP 5?
The ISPE guide providing a risk- and category-based framework for validating computerized systems, scaling effort to system complexity and novelty. The de facto global reference for CSV.
Which regulations cover GAMP 5?
ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd edition (2022). Applied against the binding requirements of 21 CFR Part 11 and EU GMP Annex 11; complementary to the FDA draft guidance on Computer Software Assurance (2022).
SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.
Get the Weekly GxP Briefing
Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.