GAMP 5
Good Automated Manufacturing Practice (ISPE)
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
The ISPE guide providing a risk- and category-based framework for validating computerized systems, scaling effort to system complexity and novelty. The de facto global reference for CSV.
GAMP 5’s central idea is that validation effort should be proportionate to risk, complexity, and novelty — not applied uniformly to every system. It does this through software categories: Category 1 (infrastructure software), Category 3 (non-configured products used as supplied), Category 4 (configured products), and Category 5 (custom or bespoke code). A Category 3 system used out of the box needs far less specification and testing than a Category 5 application written for you.
The framework is built on a V-model that pairs each specification with its corresponding verification — user requirements verified by PQ, functional specification by OQ, design specification by IQ — held together by a risk assessment that decides how deeply to test each function. It also expects you to leverage supplier activity rather than duplicate it: if a reputable vendor has tested and documented something and you have assessed them, do not re-test it wholesale.
The 2nd edition (2022) modernised the guide considerably, aligning with the FDA’s Computer Software Assurance thinking (critical thinking over documentation volume), and adding guidance for Agile and iterative delivery, cloud and SaaS, software tools, and AI/ML. The direction of travel is unmistakable: less paper for its own sake, more evidence focused where patient safety and data integrity are actually at stake.
- —Software categories: 1 infrastructure · 3 non-configured · 4 configured · 5 custom — effort scales with category.
- —V-model pairs each specification with its verification (URS↔PQ, FS↔OQ, DS↔IQ).
- —Risk assessment decides test depth; not every function warrants the same rigour.
- —Leverage supplier documentation and assessment instead of duplicating vendor testing.
- —GAMP 5 2nd edition (2022) adds Agile, cloud/SaaS, AI/ML, and aligns with FDA CSA critical thinking.
- —A guide, not a regulation — but the de facto reference inspectors expect you to have applied.
ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd edition (2022). Applied against the binding requirements of 21 CFR Part 11 and EU GMP Annex 11; complementary to the FDA final guidance on Computer Software Assurance (September 2025; draft 2022).
Frequently asked questions
What does GAMP 5 stand for?
GAMP 5 stands for Good Automated Manufacturing Practice (ISPE).
What is GAMP 5?
The ISPE guide providing a risk- and category-based framework for validating computerized systems, scaling effort to system complexity and novelty. The de facto global reference for CSV.
Which regulations cover GAMP 5?
ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd edition (2022). Applied against the binding requirements of 21 CFR Part 11 and EU GMP Annex 11; complementary to the FDA final guidance on Computer Software Assurance (September 2025; draft 2022).