Skip to content

Evidence request lists

GAMP 5 - Good Automated Manufacturing Practice

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

GAMP 5: 2nd Edition (2022) - AI/ML + Cloud + Agile + DevOps + Computer Software Assurance (CSA)

GAMP5-2nd-Edition-AI-Cloud-Agile-CSA
2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)

GAMP 5 2nd Edition (July 2022) key updates + FDA Computer Software Assurance (CSA) coordination. AI/ML SYSTEMS: dedicated guidance on validation of AI/ML in pharma (predictive maintenance + image analysis + drug discovery + clinical decision support); training + validation + retraining cycles + monitoring + bias detection + explainability + adaptive AI/ML controlled-change management; coordinated with FDA AI/ML Software as a Medical Device (SaMD) Action Plan + EU AI Act + IMDRF AI Working Group. CLOUD COMPUTING + SaaS: shared-responsibility model + supplier qualification + business continuity + data sovereignty + multi-tenant considerations + IaaS/PaaS/SaaS lifecycle differences; integrates with FedRAMP-like sector certifications + ISO 27001/27017/27018 + ISPE cloud guidance. AGILE + ITERATIVE DEVELOPMENT: scrum/kanban/SAFe adaptation; sprint-level documentation + risk assessment + accep

Artefacts an auditor will ask for
  • AI/ML validation evidence
  • Cloud supplier qualification + responsibility matrix
  • Agile + DevOps + automated testing
  • CSA adoption + risk-based assurance
Where this commonly fails
  • AI/ML not addressed
  • Cloud shared-responsibility unclear
  • Agile validation artifacts skipped
  • CSA opportunity missed

GAMP 5: 5 Software Categories (Cat 1 Infrastructure, Cat 3 Non-Configured, Cat 4 Configured, Cat 5 Custom)

GAMP5-Software-Categories
5 Software Categories (Appendix M4) - Infrastructure, Non-Configured, Configured, Custom

5 Software Categories per Appendix M4. CATEGORY 1 INFRASTRUCTURE SOFTWARE: layered software providing services + foundation (operating systems + databases + virtualisation + network OS + system utilities); validation typically: appropriately qualified by vendor + IT infrastructure standard procedures; minimal lifecycle deliverables. CATEGORY 2: DEPRECATED in 1st Edition (was firmware + later folded into other categories). CATEGORY 3 NON-CONFIGURED PRODUCTS: commercial off-the-shelf (COTS) software used without configuration (e.g. standard databases + word processors + non-configured analytical instruments software); validation: vendor assessment + IQ verifying installation + OQ verifying business processes work; lifecycle deliverables proportional. CATEGORY 4 CONFIGURED PRODUCTS: COTS software with configuration but no custom code (e.g. LIMS + ERP + MES + configured EDC); validation: con

Artefacts an auditor will ask for
  • System inventory + category assignment
  • Category-tailored validation plan
  • Configuration baseline + control
  • AI/ML system categorisation rationale
Where this commonly fails
  • Wrong category applied (over/under-validation)
  • Configuration drift without control
  • AI/ML systems treated as Cat 3/4 without rigour

GAMP 5: Data Integrity (ALCOA+), Electronic Records and 21 CFR Part 11 / EU Annex 11

GAMP5-DataIntegrity-Part11-Annex11
Data Integrity (ALCOA+), 21 CFR Part 11 + EU Annex 11 + Electronic Records

GAMP 5 DATA INTEGRITY + 21 CFR PART 11 + EU ANNEX 11 alignment. ALCOA+ PRINCIPLES (FDA + EMA + MHRA Data Integrity Guidance): ATTRIBUTABLE + LEGIBLE + CONTEMPORANEOUS + ORIGINAL + ACCURATE + COMPLETE + CONSISTENT + ENDURING + AVAILABLE. DATA INTEGRITY BY DESIGN: build controls into system design - audit trails + secure time + access controls + integrity checks + transcription error prevention + change management; rather than bolt-on. 21 CFR PART 11 (FDA Electronic Records + Electronic Signatures) - separately tracked in corpus as FDA 21 CFR Part 11 (verified) - mandates: secure audit trails + electronic signature uniqueness + binding + non-repudiation + system access controls + record retention + validation of electronic systems + records-required-to-be-maintained vs records-submitted-to-FDA. EU ANNEX 11 (Computerised Systems): mirrors Part 11 with European specifics + applies to EU GMP-

Artefacts an auditor will ask for
  • Data integrity controls + assessment
  • Audit trail + e-signature evidence
  • Part 11/Annex 11 compliance matrix
  • Inspection-ready records
Where this commonly fails
  • Audit trail gaps
  • E-signature implementation weak
  • Data integrity bolt-on not by-design
  • Part 11/Annex 11 compliance ad-hoc

GAMP 5: ISPE Guide Status, Copyright, GxP Regulatory Coordination and 2024-2025 Updates

GAMP5-CrossMapping-NIST-ISO
Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL

GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails) + RESPOND (incident + change) + RECOVER (backup + DR + business continuity); GAMP 5 + NIST CSF together cover both pharmaceutical-specific + general-IT controls. ISO/IEC 27001:2022 + ISO/IEC 27002:2022: ISMS structure for IT general controls supporting GAMP 5 CSV; ISO 27017 cloud-specific + 27018 PII-in-cloud-specific for cloud-based GxP systems. ISO 13485:2016 + IEC 62304:2006+A1:2015: medical-device QMS + medical-device software lifecycle - applies to GAMP-5-validated systems that ALSO meet medical device criteria (e.g. clinical-decision-support software + AI/ML SaMD); hybrid pharma + medical device organizations need both. ITIL 4

Artefacts an auditor will ask for
  • NIST CSF + ISO + ITIL + COBIT crosswalks
  • Hybrid pharma + medical device coverage
  • Integrated compliance program
Where this commonly fails
  • Crosswalks not maintained
  • Hybrid pharma + medical device split
  • Compliance programs siloed
GAMP5-Crosswalk-ICH-FDA-EMA-MHRA
Crosswalk to ICH Q9/Q10, FDA Part 11, EU Annex 11, MHRA Data Integrity and Sectoral Standards

GAMP 5 coordination with adjacent regulatory + standard frameworks. ICH Q9 QUALITY RISK MANAGEMENT: foundational risk-based decision making applicable to computerised systems validation; GAMP 5 implements ICH Q9 in CSV context. ICH Q10 PHARMACEUTICAL QUALITY SYSTEM: integrates GAMP 5 CSV into the broader pharmaceutical quality system including management responsibility + product realisation + continual improvement. FDA 21 CFR PART 11 - separately tracked in corpus as FDA 21 CFR Part 11 (verified); the partnership: GAMP 5 provides the lifecycle approach + Part 11 provides the electronic-records + electronic-signature specifics; CSA (Computer Software Assurance) 2022 Draft refines critical-thinking application. EU ANNEX 11 (Computerised Systems): EU equivalent to Part 11 + integrates with GMP context. MHRA DATA INTEGRITY GUIDANCE (2018 + updates): UK regulator data integrity expectations +

Artefacts an auditor will ask for
  • ICH Q9/Q10 GAMP 5 mapping
  • Part 11 + Annex 11 cross-reference
  • MHRA Data Integrity adoption
  • Sectoral standards integration
Where this commonly fails
  • ICH Q9/Q10 not integrated
  • Part 11/Annex 11 ad-hoc
  • MHRA Data Integrity not applied
  • Sectoral standards in silos
GAMP5-ISPE-Status-Copyright-Coordination
ISPE Guide Status, Copyright, GxP Regulatory Coordination and 2024-2025 Updates

GAMP 5 publication + copyright + regulatory coordination + status. PUBLICATION: ISPE GAMP 5 Guide 2nd Edition published July 2022 (supersedes 2008 1st Edition); accompanied by APPENDIX series + Companion Guides + Specialist Interest Group publications (ISPE GAMP Records and Data Integrity Guide RDIG + ISPE GAMP Operation of GxP Computerised Systems + ISPE GAMP IT Infrastructure Control and Compliance + others); the Guides are COPYRIGHTED publications + commercially licensed via ISPE bookstore. AUTHORSHIP: ISPE GAMP COMMUNITY OF PRACTICE - hundreds of pharma + biotech + medical device industry professionals + regulators + supplier representatives; chaired + edited + coordinated through ISPE. GxP REGULATORY COORDINATION: GAMP 5 is recognised as industry-standard guidance by FDA + EMA + MHRA + PMDA + Health Canada + Brazilian ANVISA + China NMPA + Singapore HSA + Australia TGA + others; ins

Artefacts an auditor will ask for
  • GAMP 5 2nd Edition licensed copy + adoption
  • Inspection-readiness program
  • Roadmap tracking + AI/ML + Cloud + CSA preparation
  • ISPE Community participation
Where this commonly fails
  • GAMP 5 1st Edition still in use
  • Inspection-readiness program missing
  • Roadmap not tracked
  • ISPE Community engagement absent
GAMP5-Implementation-Roadmap
GAMP 5 Implementation Roadmap - Organizational Roles, Training and Tooling

GAMP 5 implementation roadmap for an organization. ORGANIZATIONAL ROLES: (a) QUALITY ASSURANCE - GAMP 5 program ownership + compliance oversight; (b) VALIDATION LEAD - per-system validation execution + traceability + reporting; (c) IT SYSTEMS OWNER - business + technical accountability + lifecycle management; (d) BUSINESS PROCESS OWNER - URS + UAT + business-side validation acceptance; (e) SUPPLIER MANAGEMENT - supplier qualification + audit + ongoing performance; (f) DATA INTEGRITY OWNER - ALCOA+ + audit-trail + Part 11/Annex 11 compliance; (g) COMPUTER SYSTEM VALIDATION (CSV) ENGINEERS - protocol authoring + execution + reporting; (h) AI/ML SPECIALIST LEAD - emerging-tech category 5 systems; (i) CLOUD/SaaS RELATIONSHIP MANAGER - shared-responsibility navigation. TRAINING: GAMP 5 awareness training (all + role-specific); ISPE GAMP courses + Computer System Validation + Data Integrity +

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Training records + CPD evidence
  • Tool adoption + integration
  • Metrics dashboard + management review
Where this commonly fails
  • Roles undefined
  • Training inconsistent
  • Tooling fragmented
  • Metrics not tracked
GAMP5-Status-2024-2025-CSA-AI
GAMP 5 Status, FDA CSA Final Guidance and AI/ML in Pharma 2024-2025

GAMP 5 status + emerging regulatory developments 2024-2025. STATUS: GAMP 5 2nd Edition (2022) is the current ISPE Guide + adoption progressing in industry; 1st Edition users transitioning; new systems implementing per 2nd Edition. FDA CSA (COMPUTER SOFTWARE ASSURANCE) FINAL GUIDANCE - anticipated 2025-2026; Draft Guidance issued 2022 + has signalled the FDA's risk-based + critical-thinking + assurance-by-assessment approach for non-product-and-process-related software; GAMP 5 2nd Edition critical-thinking emphasis aligns; FINAL GUIDANCE will codify FDA's expectations + may reduce some prescriptive validation testing for low-risk systems. AI/ML IN PHARMA + BIOTECH: 2024-2025 ISPE GAMP Community of Practice publications on AI/ML validation + 2024 ISPE AI/ML in GxP whitepaper; FDA AI/ML SaMD Action Plan + Predetermined Change Control Plan (PCCP); EU AI Act compliance for pharma AI systems (

Artefacts an auditor will ask for
  • 2nd Edition implementation evidence
  • CSA Draft + Final Guidance tracking
  • AI/ML use-case validation evidence
  • Remote-inspection readiness + ESG tracking
Where this commonly fails
  • 1st Edition still in production
  • CSA not anticipated
  • AI/ML not addressed
  • Remote-inspection unprepared

GAMP 5: Risk-Based Approach, Critical Thinking and 5 Key Concepts

GAMP5-Risk-CriticalThinking
Risk-Based Approach, Critical Thinking and 5 Key Concepts

GAMP 5 RISK-BASED + LIFE-CYCLE + LEVERAGE-SUPPLIER + SCALABLE + CRITICAL-THINKING approach. KEY CONCEPT 1 RISK-BASED: validation effort proportional to risk to product quality + patient safety + data integrity + regulatory impact; risk assessment per ICH Q9 + ISO 31000 + at system level + business process level + functional level + leverages prior knowledge. KEY CONCEPT 2 LIFE-CYCLE: V-Model lifecycle integrating SPECIFICATION (URS + FS + DS) with VERIFICATION (IQ + OQ + PQ); reuse across system lifecycle; from concept to retirement. KEY CONCEPT 3 LEVERAGE SUPPLIER INVOLVEMENT: qualified supplier provides documentation + testing + tooling + reduce duplication; supplier audit + assessment program; supplier-provided documentation accepted when leverage is justified. KEY CONCEPT 4 SCALABILITY: approach tailored to system complexity + risk + business criticality; small instruments to enterpr

Artefacts an auditor will ask for
  • Risk assessment per system
  • Lifecycle documents
  • Supplier qualification + leverage rationale
  • Critical thinking documented justifications
Where this commonly fails
  • Over-validation (checkbox)
  • Under-validation (gaps)
  • Supplier leverage unjustified
  • Critical thinking absent or undocumented

GAMP 5: Supplier Assessment, Operational Phase, Change Control and Periodic Review

GAMP5-Supplier-Operations-Change-Periodic
Supplier Assessment, Operational Phase, Change Control and Periodic Review

GAMP 5 SUPPLIER ASSESSMENT + OPERATIONAL PHASE + CHANGE CONTROL + PERIODIC REVIEW. SUPPLIER ASSESSMENT: pre-engagement qualification + risk-based depth (lighter for Cat 1/3 + deeper for Cat 4/5); supplier audit (on-site or remote) + supplier capability assessment + documentation review + ongoing performance monitoring; supplier service-level agreements + supplier QMS evidence; multi-supplier supply chain visibility. OPERATIONAL PHASE: post-go-live activities ensuring system remains validated + compliant + fit for purpose; INCIDENT MANAGEMENT (with root-cause analysis + corrective + preventive actions); PROBLEM MANAGEMENT (recurring incident trends); CHANGE MANAGEMENT (controlled changes with risk assessment + impact analysis + regression testing + change-impact-on-validation determination); CONFIGURATION MANAGEMENT (baseline + version control); BACKUP/RESTORE + ARCHIVE; BUSINESS CONTINUI

Artefacts an auditor will ask for
  • Supplier qualification records
  • Incident/change/config logs
  • Periodic review records + decisions
  • Decommissioning plan + execution records
Where this commonly fails
  • Supplier qualification superficial
  • Change impact assessment skipped
  • Periodic review pro-forma
  • Decommissioning without records

GAMP 5: V-Model Lifecycle and Specification Documents (URS, FS, DS, IQ, OQ, PQ)

GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ
V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability

V-Model Lifecycle - specification phases mirrored by verification phases. SPECIFICATION SIDE: (a) USER REQUIREMENTS SPECIFICATION (URS) - what the business needs the system to do + GxP requirements + regulatory + audit + user-defined functional + non-functional; (b) FUNCTIONAL SPECIFICATION (FS) - what the system does to meet URS; (c) DESIGN SPECIFICATION (DS) - how the system is designed + architecture + data flows + interfaces. VERIFICATION SIDE: (a) INSTALLATION QUALIFICATION (IQ) - verifies system installed per design; (b) OPERATIONAL QUALIFICATION (OQ) - verifies system operates per functional specification under simulated operating conditions; (c) PERFORMANCE QUALIFICATION (PQ) - verifies system performs per URS under actual operating conditions including throughput + reliability + business processes; (d) USER ACCEPTANCE TESTING (UAT) overlapping PQ. TRACEABILITY MATRIX: links URS

Artefacts an auditor will ask for
  • Specification document set
  • Qualification protocol + execution records
  • Traceability matrix maintained
  • Risk-tiered testing
Where this commonly fails
  • Specification incomplete or stale
  • Qualification skipped
  • Traceability matrix missing
  • Risk-proportionate sizing absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GAMP 5 - Good Automated Manufacturing Practice framework page.