GAMP 5 - Good Automated Manufacturing Practice
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
GAMP 5: 2nd Edition (2022) - AI/ML + Cloud + Agile + DevOps + Computer Software Assurance (CSA)
GAMP 5 2nd Edition (July 2022) key updates + FDA Computer Software Assurance (CSA) coordination. AI/ML SYSTEMS: dedicated guidance on validation of AI/ML in pharma (predictive maintenance + image analysis + drug discovery + clinical decision support); training + validation + retraining cycles + monitoring + bias detection + explainability + adaptive AI/ML controlled-change management; coordinated with FDA AI/ML Software as a Medical Device (SaMD) Action Plan + EU AI Act + IMDRF AI Working Group. CLOUD COMPUTING + SaaS: shared-responsibility model + supplier qualification + business continuity + data sovereignty + multi-tenant considerations + IaaS/PaaS/SaaS lifecycle differences; integrates with FedRAMP-like sector certifications + ISO 27001/27017/27018 + ISPE cloud guidance. AGILE + ITERATIVE DEVELOPMENT: scrum/kanban/SAFe adaptation; sprint-level documentation + risk assessment + accep
- AI/ML validation evidence
- Cloud supplier qualification + responsibility matrix
- Agile + DevOps + automated testing
- CSA adoption + risk-based assurance
- AI/ML not addressed
- Cloud shared-responsibility unclear
- Agile validation artifacts skipped
- CSA opportunity missed
GAMP 5: 5 Software Categories (Cat 1 Infrastructure, Cat 3 Non-Configured, Cat 4 Configured, Cat 5 Custom)
5 Software Categories per Appendix M4. CATEGORY 1 INFRASTRUCTURE SOFTWARE: layered software providing services + foundation (operating systems + databases + virtualisation + network OS + system utilities); validation typically: appropriately qualified by vendor + IT infrastructure standard procedures; minimal lifecycle deliverables. CATEGORY 2: DEPRECATED in 1st Edition (was firmware + later folded into other categories). CATEGORY 3 NON-CONFIGURED PRODUCTS: commercial off-the-shelf (COTS) software used without configuration (e.g. standard databases + word processors + non-configured analytical instruments software); validation: vendor assessment + IQ verifying installation + OQ verifying business processes work; lifecycle deliverables proportional. CATEGORY 4 CONFIGURED PRODUCTS: COTS software with configuration but no custom code (e.g. LIMS + ERP + MES + configured EDC); validation: con
- System inventory + category assignment
- Category-tailored validation plan
- Configuration baseline + control
- AI/ML system categorisation rationale
- Wrong category applied (over/under-validation)
- Configuration drift without control
- AI/ML systems treated as Cat 3/4 without rigour
GAMP 5: Data Integrity (ALCOA+), Electronic Records and 21 CFR Part 11 / EU Annex 11
GAMP 5 DATA INTEGRITY + 21 CFR PART 11 + EU ANNEX 11 alignment. ALCOA+ PRINCIPLES (FDA + EMA + MHRA Data Integrity Guidance): ATTRIBUTABLE + LEGIBLE + CONTEMPORANEOUS + ORIGINAL + ACCURATE + COMPLETE + CONSISTENT + ENDURING + AVAILABLE. DATA INTEGRITY BY DESIGN: build controls into system design - audit trails + secure time + access controls + integrity checks + transcription error prevention + change management; rather than bolt-on. 21 CFR PART 11 (FDA Electronic Records + Electronic Signatures) - separately tracked in corpus as FDA 21 CFR Part 11 (verified) - mandates: secure audit trails + electronic signature uniqueness + binding + non-repudiation + system access controls + record retention + validation of electronic systems + records-required-to-be-maintained vs records-submitted-to-FDA. EU ANNEX 11 (Computerised Systems): mirrors Part 11 with European specifics + applies to EU GMP-
- Data integrity controls + assessment
- Audit trail + e-signature evidence
- Part 11/Annex 11 compliance matrix
- Inspection-ready records
- Audit trail gaps
- E-signature implementation weak
- Data integrity bolt-on not by-design
- Part 11/Annex 11 compliance ad-hoc
GAMP 5: ISPE Guide Status, Copyright, GxP Regulatory Coordination and 2024-2025 Updates
GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails) + RESPOND (incident + change) + RECOVER (backup + DR + business continuity); GAMP 5 + NIST CSF together cover both pharmaceutical-specific + general-IT controls. ISO/IEC 27001:2022 + ISO/IEC 27002:2022: ISMS structure for IT general controls supporting GAMP 5 CSV; ISO 27017 cloud-specific + 27018 PII-in-cloud-specific for cloud-based GxP systems. ISO 13485:2016 + IEC 62304:2006+A1:2015: medical-device QMS + medical-device software lifecycle - applies to GAMP-5-validated systems that ALSO meet medical device criteria (e.g. clinical-decision-support software + AI/ML SaMD); hybrid pharma + medical device organizations need both. ITIL 4
- NIST CSF + ISO + ITIL + COBIT crosswalks
- Hybrid pharma + medical device coverage
- Integrated compliance program
- Crosswalks not maintained
- Hybrid pharma + medical device split
- Compliance programs siloed
GAMP 5 coordination with adjacent regulatory + standard frameworks. ICH Q9 QUALITY RISK MANAGEMENT: foundational risk-based decision making applicable to computerised systems validation; GAMP 5 implements ICH Q9 in CSV context. ICH Q10 PHARMACEUTICAL QUALITY SYSTEM: integrates GAMP 5 CSV into the broader pharmaceutical quality system including management responsibility + product realisation + continual improvement. FDA 21 CFR PART 11 - separately tracked in corpus as FDA 21 CFR Part 11 (verified); the partnership: GAMP 5 provides the lifecycle approach + Part 11 provides the electronic-records + electronic-signature specifics; CSA (Computer Software Assurance) 2022 Draft refines critical-thinking application. EU ANNEX 11 (Computerised Systems): EU equivalent to Part 11 + integrates with GMP context. MHRA DATA INTEGRITY GUIDANCE (2018 + updates): UK regulator data integrity expectations +
- ICH Q9/Q10 GAMP 5 mapping
- Part 11 + Annex 11 cross-reference
- MHRA Data Integrity adoption
- Sectoral standards integration
- ICH Q9/Q10 not integrated
- Part 11/Annex 11 ad-hoc
- MHRA Data Integrity not applied
- Sectoral standards in silos
GAMP 5 publication + copyright + regulatory coordination + status. PUBLICATION: ISPE GAMP 5 Guide 2nd Edition published July 2022 (supersedes 2008 1st Edition); accompanied by APPENDIX series + Companion Guides + Specialist Interest Group publications (ISPE GAMP Records and Data Integrity Guide RDIG + ISPE GAMP Operation of GxP Computerised Systems + ISPE GAMP IT Infrastructure Control and Compliance + others); the Guides are COPYRIGHTED publications + commercially licensed via ISPE bookstore. AUTHORSHIP: ISPE GAMP COMMUNITY OF PRACTICE - hundreds of pharma + biotech + medical device industry professionals + regulators + supplier representatives; chaired + edited + coordinated through ISPE. GxP REGULATORY COORDINATION: GAMP 5 is recognised as industry-standard guidance by FDA + EMA + MHRA + PMDA + Health Canada + Brazilian ANVISA + China NMPA + Singapore HSA + Australia TGA + others; ins
- GAMP 5 2nd Edition licensed copy + adoption
- Inspection-readiness program
- Roadmap tracking + AI/ML + Cloud + CSA preparation
- ISPE Community participation
- GAMP 5 1st Edition still in use
- Inspection-readiness program missing
- Roadmap not tracked
- ISPE Community engagement absent
GAMP 5 implementation roadmap for an organization. ORGANIZATIONAL ROLES: (a) QUALITY ASSURANCE - GAMP 5 program ownership + compliance oversight; (b) VALIDATION LEAD - per-system validation execution + traceability + reporting; (c) IT SYSTEMS OWNER - business + technical accountability + lifecycle management; (d) BUSINESS PROCESS OWNER - URS + UAT + business-side validation acceptance; (e) SUPPLIER MANAGEMENT - supplier qualification + audit + ongoing performance; (f) DATA INTEGRITY OWNER - ALCOA+ + audit-trail + Part 11/Annex 11 compliance; (g) COMPUTER SYSTEM VALIDATION (CSV) ENGINEERS - protocol authoring + execution + reporting; (h) AI/ML SPECIALIST LEAD - emerging-tech category 5 systems; (i) CLOUD/SaaS RELATIONSHIP MANAGER - shared-responsibility navigation. TRAINING: GAMP 5 awareness training (all + role-specific); ISPE GAMP courses + Computer System Validation + Data Integrity +
- Role inventory + RACI
- Training records + CPD evidence
- Tool adoption + integration
- Metrics dashboard + management review
- Roles undefined
- Training inconsistent
- Tooling fragmented
- Metrics not tracked
GAMP 5 status + emerging regulatory developments 2024-2025. STATUS: GAMP 5 2nd Edition (2022) is the current ISPE Guide + adoption progressing in industry; 1st Edition users transitioning; new systems implementing per 2nd Edition. FDA CSA (COMPUTER SOFTWARE ASSURANCE) FINAL GUIDANCE - anticipated 2025-2026; Draft Guidance issued 2022 + has signalled the FDA's risk-based + critical-thinking + assurance-by-assessment approach for non-product-and-process-related software; GAMP 5 2nd Edition critical-thinking emphasis aligns; FINAL GUIDANCE will codify FDA's expectations + may reduce some prescriptive validation testing for low-risk systems. AI/ML IN PHARMA + BIOTECH: 2024-2025 ISPE GAMP Community of Practice publications on AI/ML validation + 2024 ISPE AI/ML in GxP whitepaper; FDA AI/ML SaMD Action Plan + Predetermined Change Control Plan (PCCP); EU AI Act compliance for pharma AI systems (
- 2nd Edition implementation evidence
- CSA Draft + Final Guidance tracking
- AI/ML use-case validation evidence
- Remote-inspection readiness + ESG tracking
- 1st Edition still in production
- CSA not anticipated
- AI/ML not addressed
- Remote-inspection unprepared
GAMP 5: Risk-Based Approach, Critical Thinking and 5 Key Concepts
GAMP 5 RISK-BASED + LIFE-CYCLE + LEVERAGE-SUPPLIER + SCALABLE + CRITICAL-THINKING approach. KEY CONCEPT 1 RISK-BASED: validation effort proportional to risk to product quality + patient safety + data integrity + regulatory impact; risk assessment per ICH Q9 + ISO 31000 + at system level + business process level + functional level + leverages prior knowledge. KEY CONCEPT 2 LIFE-CYCLE: V-Model lifecycle integrating SPECIFICATION (URS + FS + DS) with VERIFICATION (IQ + OQ + PQ); reuse across system lifecycle; from concept to retirement. KEY CONCEPT 3 LEVERAGE SUPPLIER INVOLVEMENT: qualified supplier provides documentation + testing + tooling + reduce duplication; supplier audit + assessment program; supplier-provided documentation accepted when leverage is justified. KEY CONCEPT 4 SCALABILITY: approach tailored to system complexity + risk + business criticality; small instruments to enterpr
- Risk assessment per system
- Lifecycle documents
- Supplier qualification + leverage rationale
- Critical thinking documented justifications
- Over-validation (checkbox)
- Under-validation (gaps)
- Supplier leverage unjustified
- Critical thinking absent or undocumented
GAMP 5: Supplier Assessment, Operational Phase, Change Control and Periodic Review
GAMP 5 SUPPLIER ASSESSMENT + OPERATIONAL PHASE + CHANGE CONTROL + PERIODIC REVIEW. SUPPLIER ASSESSMENT: pre-engagement qualification + risk-based depth (lighter for Cat 1/3 + deeper for Cat 4/5); supplier audit (on-site or remote) + supplier capability assessment + documentation review + ongoing performance monitoring; supplier service-level agreements + supplier QMS evidence; multi-supplier supply chain visibility. OPERATIONAL PHASE: post-go-live activities ensuring system remains validated + compliant + fit for purpose; INCIDENT MANAGEMENT (with root-cause analysis + corrective + preventive actions); PROBLEM MANAGEMENT (recurring incident trends); CHANGE MANAGEMENT (controlled changes with risk assessment + impact analysis + regression testing + change-impact-on-validation determination); CONFIGURATION MANAGEMENT (baseline + version control); BACKUP/RESTORE + ARCHIVE; BUSINESS CONTINUI
- Supplier qualification records
- Incident/change/config logs
- Periodic review records + decisions
- Decommissioning plan + execution records
- Supplier qualification superficial
- Change impact assessment skipped
- Periodic review pro-forma
- Decommissioning without records
GAMP 5: V-Model Lifecycle and Specification Documents (URS, FS, DS, IQ, OQ, PQ)
V-Model Lifecycle - specification phases mirrored by verification phases. SPECIFICATION SIDE: (a) USER REQUIREMENTS SPECIFICATION (URS) - what the business needs the system to do + GxP requirements + regulatory + audit + user-defined functional + non-functional; (b) FUNCTIONAL SPECIFICATION (FS) - what the system does to meet URS; (c) DESIGN SPECIFICATION (DS) - how the system is designed + architecture + data flows + interfaces. VERIFICATION SIDE: (a) INSTALLATION QUALIFICATION (IQ) - verifies system installed per design; (b) OPERATIONAL QUALIFICATION (OQ) - verifies system operates per functional specification under simulated operating conditions; (c) PERFORMANCE QUALIFICATION (PQ) - verifies system performs per URS under actual operating conditions including throughput + reliability + business processes; (d) USER ACCEPTANCE TESTING (UAT) overlapping PQ. TRACEABILITY MATRIX: links URS
- Specification document set
- Qualification protocol + execution records
- Traceability matrix maintained
- Risk-tiered testing
- Specification incomplete or stale
- Qualification skipped
- Traceability matrix missing
- Risk-proportionate sizing absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GAMP 5 - Good Automated Manufacturing Practice framework page.