Good Practice Guide: Compliant GxP Computerised Systems
The ISPE GAMP 5 Second Edition provides a risk-based approach for the validation of computerised systems used in pharmaceutical manufacturing. Updates the original 2008 guide to reflect cloud computing, modern software development, and agile methodologies.
What this does not cover
stated in the document's own scope- Provides validation guidance, not a binding regulation; the legal requirements are 21 CFR Part 11 and EU GMP Annex 11.
- Covers computerised-system validation, not the engineering qualification of manufacturing equipment, which follows ASTM E2500 / ISPE Baseline Guide Vol. 5.
- Addresses system compliance and data integrity broadly, but does not itself define the record-retention or signature legal specifics, which live in Part 11 / Annex 11.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
ISPE GAMP 5 is the industry reference for keeping computerised systems used in regulated activities compliant and fit for intended use. Its full title is GAMP 5: A Risk-Based Approach to Compliant GxP Computerised Systems. It frames validation around understanding the process the system supports, the risk it carries, and the way the software was built and supplied — scaling effort to risk and novelty rather than applying one heavy protocol to every system. The Second Edition (2022) updates the 2008 guide for cloud and platform services, modern and iterative software development, agile delivery, and the critical-thinking approach associated with Computer Software Assurance.
Scope & applicability
All GxP computerised systems in regulated industries: process control systems, laboratory instruments, QMS, LIMS, DCS, MES, and clinical data systems.
Legal basis & how it acquires force
GAMP 5 is a Good Practice Guide published by ISPE; it is guidance, not regulation, and imposes no legal obligation of its own. The binding requirements it helps satisfy are the electronic-records and computerised-systems rules of the relevant GxP framework — 21 CFR Part 11 in the US and EU GMP Annex 11 in Europe — together with the underlying predicate GMP/GCP/GLP rules. A company complies with those instruments; GAMP 5 supplies a recognised, risk-based methodology for demonstrating that a computerised system is validated and controlled.
Document structure
| Part | Covers |
|---|---|
| Life cycle approach | The system life cycle from concept through operation to retirement, scaled to risk |
| Software categories | Category 1 (infrastructure), 3 (non-configured), 4 (configured), and 5 (custom) and their differing validation effort |
| Quality risk management | Applying risk management to focus specification and verification on what affects patient safety, product quality, and data integrity |
| Supplier involvement | Leveraging supplier activity and documentation to avoid duplicating effort |
| Appendices — management, development, operation | Detailed appendices on planning, specification, testing, and operational control |
| Second-edition topics | Cloud/IT service providers, agile and iterative development, and critical-thinking / software-assurance concepts |
Key requirements
- Software category classification: Category 1 (infrastructure), 3 (non-configured), 4 (configured), 5 (bespoke)
- Risk-based validation approach — validation effort proportional to risk and complexity
- Supplier assessment commensurate with system category and risk
- Data integrity by design — ALCOA+ principles built into system specification
- Validation lifecycle: specification → testing → operation → review → retirement
Implementation tips
- Category 4 systems (like SAP, Veeva, MasterControl) require configuration specification documentation that maps to URS
- Cloud-hosted systems need specific supplier qualification addressing data sovereignty, security, and audit rights
- Agile teams: validation strategy must define how user stories link to validation testing evidence
Revision notes
Second Edition April 2022. Major updates: cloud computing guidance, agile methodology, modern software development, updated category definitions. First Edition 2008 is obsolete — transition to 2022 edition.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
GAMP 5 aligns with 21 CFR Part 11 and EU GMP Annex 11 on electronic records and computerised systems, and with the data-integrity expectations set out in PIC/S PI 041 and the MHRA data-integrity guidance. Its risk-based logic is consistent with ICH Q9 quality risk management, and the Second Edition’s critical-thinking framing tracks the FDA’s Computer Software Assurance (CSA) thinking for production and quality-system software.
ISPE GAMP 5 (2022): frequently asked questions
Quick answers to common questions about ISPE GAMP 5 (2022).
What do the GAMP 5 software categories mean?
They scale validation effort to the nature of the software: Category 1 is infrastructure, Category 3 is non-configured (used as supplied) products, Category 4 is configured products, and Category 5 is custom-developed software — which carries the most rigour.
What changed in the GAMP 5 Second Edition?
The 2022 Second Edition updated the 2008 guide for cloud and IT service providers, modern and agile software development, and critical-thinking / Computer Software Assurance concepts, while keeping the risk-based life-cycle framework.
Is GAMP 5 the same as 21 CFR Part 11?
No. Part 11 (and EU GMP Annex 11) are the binding rules for electronic records and computerised systems; GAMP 5 is ISPE guidance describing a risk-based way to meet them.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.