Book a demo

3 July 2025

What is GAMP 5? 

Author: Ben Finnan

Reviewed by: Liam Coffey

Last updated: July 8, 2026

Good Automated Manufacturing Practice (GAMP) 5 is the risk-based guide that pharmaceutical and life sciences companies rely on to validate computerized systems. The International Society for Pharmaceutical Engineering (ISPE) published the fifth and current version to help teams simplify validation and reduce unnecessary documentation.

For many organizations, validation demands consume a disproportionate share of team time. GAMP 5 addresses this by scaling effort to risk — so teams focus on what matters most for audit readiness and patient safety.

This guide covers what GAMP 5 is and how its software categories and key principles work. It also explains what changed in the Second Edition and how GAMP 5 relates to 21 CFR Part 11 and EU Annex 11. Validation teams and compliance professionals will find practical context here.

What is GAMP 5?

GAMP 5 is the latest version of an industry resource from the International Society for Pharmaceutical Engineering (ISPE). GAMP stands for Good Automated Manufacturing Practice. ISPE first published the guide in 2001 and has updated it several times since. ISPE released the current edition — the GAMP 5 Second Edition — in 2022.

Since its inception, GAMP 5 has helped pharmaceutical professionals design, test, manage, and maintain automated and computerized systems throughout their entire life cycle. The ISPE GAMP 5 guide provides practical advice on getting these systems fit for use and in line with regulatory requirements.

GAMP 5 takes a risk-based approach to validation. It focuses effort on areas that most affect product quality and compliance. GAMP 5 has become a widely adopted guidance document across regulated industries.

Keep in mind: GAMP 5 guides Computer System Validation (CSV) as well as Commissioning, Qualification, and Validation (CQV) processes. This makes it helpful for various automated systems in pharmaceutical manufacturing, including compliant GxP computerized systems.

Is GAMP 5 an official regulation?

GAMP 5 is an industry guidance document, not an official regulation. Regulated companies apply it to meet requirements set by the Food and Drug Administration (FDA), the European Medicines Agency (EMA), and similar bodies. These requirements cover patient safety, data integrity, product quality, and regulatory compliance.

Regulated companies in pharma and beyond use GAMP 5’s guidelines to demonstrate compliance. Specifically, organizations use GAMP 5 to demonstrate compliance with FDA 21 CFR Part 11, EU Annex 11, and Pharmaceutical Inspection Co-operation Scheme (PIC/S) guidelines. GAMP 5 is a well-established, widely adopted resource for regulated industries.

Key principles of GAMP 5

Five core principles underpin GAMP 5, guiding how life sciences professionals design, deploy, operate, and maintain their systems. Understanding these principles helps organizations apply GAMP 5 guidance proportionally.

Risk-based approach

At its heart, GAMP 5 focuses validation effort proportionally to risk. GAMP 5 directs the deepest testing and documentation toward systems with the highest impact on patient safety or product quality. Lower-risk infrastructure components receive scaled-down requirements.

GAMP 5 shows teams how to design and validate systems against FDA, EMA, and similar regulatory requirements. This risk-based approach directs validation effort toward systems where impact on product quality and patient safety is highest.

Scalable life cycle activities

GAMP 5 suggests looking at the whole system — software, hardware, operating systems, and automation — as one big picture. This means thinking about how each part interacts and relies on the others — from design and testing through full operation.

Validation activities scale based on system complexity and the risk it poses. A simple, off-the-shelf tool does not require the same depth of testing as a custom-built manufacturing execution system. GAMP 5 gives teams the guidance to calibrate effort accordingly.

Leveraging supplier involvement

GAMP 5 encourages organizations to leverage supplier testing documentation and quality management records. If a software vendor already conducts rigorous testing and maintains quality records, teams can build on that existing work and eliminate redundant testing. This reduces redundant validation effort without sacrificing compliance.

Product and process understanding

Understanding the intended use of a system drives the scope of validation. GAMP 5 emphasizes that teams must understand a system’s intended function and identify which parts carry GxP impact. This understanding shapes risk assessments and testing strategies.

Knowledge management

In the life sciences industry, organizations must keep records organized and traceable, in line with regulatory requirements. GAMP 5 makes document management easier by providing clear guidelines on how to document every step of the system life cycle.

Beyond documentation, knowledge management encompasses institutional knowledge and lessons learned. Teams that capture and share validation knowledge across projects avoid repeating mistakes and build stronger compliance programs over time.

GAMP 5 software categories

One of the most practical elements of GAMP 5 is its software categorization system. GAMP 5 categories classify software by complexity and the level of validation each type requires. Validation requirements scale with complexity — from configuration records for infrastructure software to full life cycle documentation for custom-built applications.

GAMP 5 defines four active categories. (ISPE removed Category 2 for firmware in later editions, absorbing firmware into the remaining categories.)

Category 1 — infrastructure software

Infrastructure software covers foundational components such as operating systems and database engines. Organizations across life sciences rely on these well-established products. Validation typically requires only configuration records and installation verification. Examples include Windows Server and Oracle databases.

Category 3 — non-configured products

Category 3 covers off-the-shelf software used as-is, without configuration changes. Think of tools like Microsoft Excel or a standard PDF reader used in a GxP context. These require installation verification and functional testing of GxP-relevant features. Because the software runs without customization, validation scope remains narrow.

Category 4 — configured products

Configured products are commercial software packages customized through configuration, not custom code. Common examples include Enterprise Resource Planning (ERP) and Laboratory Information Management System (LIMS) platforms. Validation focuses on risk-based testing of configurations and workflows to confirm the system performs as intended in the user’s environment.

Category 5 — custom applications

Category 5 applies to fully custom-built software or heavily customized systems. Because the code is unique to the organization, these applications require the most rigorous validation. This includes full development life cycle documentation and code reviews. Testing spans from unit level through the full IQ/OQ/PQ qualification sequence.

The GAMP 5 V-model

The V-model is a core GAMP 5 framework. It maps development activities on the left side to corresponding testing activities on the right. It provides a structured way to ensure a matching test verifies every design decision.

On the left side: User Requirements Specification (URS) leads to Functional Specification (FS), which leads to Design Specification (DS). On the right side: each specification maps to a qualification. PQ covers user requirements and OQ covers functional specifications; IQ maps to design specifications.

The V-model ensures traceability between specifications and test results. For GAMP 5 validation of higher-category systems (Category 4 and 5), this traceability is essential for audit defense and regulatory compliance.

The GAMP 5 Second Edition acknowledges that modern development does not always follow a linear path. It includes guidance on Agile and iterative development approaches, recognizing that teams can apply the V-model’s principles within shorter development cycles.

GAMP 5 life cycle stages

GAMP 5 defines four life cycle stages that cover a computerized system from initial conception through retirement. Each stage carries specific validation expectations.

Concept: Teams define business needs and conduct an initial risk assessment to determine whether the system falls under GxP requirements. This stage sets the foundation for proportional validation.

Project: Design, develop, test, and deploy the system. This is where the V-model applies — teams write specifications and match them with corresponding qualification tests before the system goes live.

Operations: Once live, the system requires ongoing maintenance, change control, periodic reviews, and incident management. Validation continues throughout the operational life of the system.

Retirement: When a system reaches end-of-life, GAMP 5 provides guidance on data migration, archival, decommissioning procedures, and compliance documentation. Proper retirement ensures data integrity and regulatory compliance even after the system is no longer in use.

What changed in the GAMP 5 Second Edition

ISPE released the GAMP 5 Second Edition in 2022, updating the guide to reflect how the industry has evolved since the original publication. Here are the key changes.

Emphasis on professional judgment. The Second Edition prioritizes professional judgment and proportional risk assessment. Teams calibrate validation effort to actual system risk. This aligns with a broader industry shift toward proportional validation.

Cloud computing and Software as a Service (SaaS) validation. The updated guide addresses the reality that many GxP systems now run in the cloud. It provides guidance on validating Software as a Service (SaaS) platforms, shared responsibility models, supplier qualification for cloud providers, and data residency considerations.

Updated data integrity expectations. The Second Edition strengthens its guidance on ALCOA++ principles. These cover Attributable, Legible, Contemporaneous, Original, and Accurate data — plus Complete, Consistent, Enduring, and Available. Data integrity remains a top regulatory priority.

Cybersecurity considerations. For the first time, GAMP 5 explicitly addresses cybersecurity as a factor in computerized system validation. Modern systems face threats that did not exist when ISPE wrote the original guide.

Alignment with Computer Software Assurance (CSA) principles. The Second Edition reflects the FDA’s shift toward CSA, emphasizing risk-based assurance calibrated to actual system risk. This update brings GAMP 5 closer to modern CSV practices.

Greater emphasis on supplier documentation. The update encourages organizations to leverage vendor documentation and testing records more effectively, reducing duplicative effort and maintaining compliance.

How GAMP 5 relates to 21 CFR Part 11 and EU Annex 11

GAMP 5 fits alongside regulatory requirements like 21 CFR Part 11 and EU Annex 11, and all three work in concert.

GAMP 5 is an ISPE industry guidance document. It explains how to validate computerized systems using a risk-based, life cycle approach.

21 CFR Part 11 is a US federal regulation from the FDA. It defines what is required for electronic records and electronic signatures — including audit trails, access controls, data integrity measures, and electronic signature requirements.

EU Annex 11 is a European regulation that sets requirements for computerized systems used in Good Manufacturing Practice (GMP) environments. It addresses the same subject matter as 21 CFR Part 11, applied within the European regulatory framework.

In practice, GAMP 5 provides the methodology for meeting the requirements of both 21 CFR Part 11 and EU Annex 11. Organizations that follow GAMP 5’s risk-based guidance position themselves to satisfy these regulatory standards effectively.

GAMP 5 and Computer Software Assurance (CSA)

The FDA has been shifting its approach to software validation. The agency is moving toward Computer Software Assurance (CSA), a risk-based alternative to traditional CSV.

Computer Software Assurance (CSA) applies proportional, risk-based testing where effort aligns with actual risk. Validation effort scales with the risk level of each feature.

The GAMP 5 Second Edition aligns closely with CSA principles. Both GAMP 5 and CSA direct validation effort toward actual risk, calibrating testing depth to the compliance impact of each system. For regulated companies, the two approaches reinforce each other’s emphasis on proportional validation.

GAMP 5’s role in digital transformation

The life sciences industry is adopting new technologies at an accelerating rate. The ISPE GAMP Community of Practice (CoP) regularly reviews and updates best practices. This keeps the guide current as the industry evolves.

Pharmaceutical companies are adopting cloud computing, AI, Internet of Things (IoT), and advanced automation to accelerate production and inform decisions with real-time data. GAMP 5 supports this shift with guidance on validating these modern systems.

Because software development rarely follows a linear path, GAMP 5 provides flexible, iterative guidance that adapts as systems evolve.

GAMP 5 provides guidance on validating cloud data storage and access controls against regulatory requirements. It also covers how automation can maintain system integrity throughout the life cycle.

This evolution mirrors broader industry movements like Validation 4.0 and Pharma 4.0. Both are reshaping how life sciences organizations approach quality and compliance in a digital-first world.

Who should use GAMP 5?

GAMP 5 is not limited to computer experts or people with “validation” in their job title. It is useful for anyone working with computerized and automated systems in pharmaceutical or life sciences companies, including:

  • Quality Assurance (QA) teams: When reviewing how teams build and test automated systems, GAMP 5 shows QA specialists what to look for. This guidance helps ensure quality risk management and that systems meet safety standards.
  • IT and automation teams: Professionals who design, build, maintain, or support automated systems can use GAMP 5 to confirm everything runs in line with regulations.
  • Validation and compliance specialists: GAMP 5 gives these specialists a structured way to confirm automated systems perform as required. It removes the burden of over-testing low-risk areas.
  • Engineers: Engineers who design equipment or work with manufacturing processes can use GAMP 5 to meet compliance requirements. It helps them align hardware, software, automation systems, and supporting infrastructure.
  • Project managers: Project managers can use GAMP 5 to guide timelines and team responsibilities when installing or updating a system.

How much does GAMP cost?

GAMP 5 prices vary depending on ISPE membership status. Members get the guide for $395 USD — nearly half the non-member price ($770 USD).

There is also special pricing for professionals in emerging economies, making it more affordable worldwide.

Frequently asked questions

What does GAMP stand for?

GAMP stands for Good Automated Manufacturing Practice. ISPE publishes these guidelines as risk-based guidance for validating computerized systems in regulated industries.

What are the GAMP 5 software categories?

GAMP 5 defines four active software categories: Category 1 (infrastructure software), Category 3 (non-configured products), Category 4 (configured products), and Category 5 (custom applications). Each category carries different validation expectations based on complexity and risk.

Is GAMP 5 a regulation or a guideline?

ISPE publishes GAMP 5 as an industry guide — not a regulation. Organizations widely use it to meet regulatory requirements set by the FDA and EMA.

What is the difference between GAMP 5 and 21 CFR Part 11?

GAMP 5 is an industry guidance document that explains how to validate computerized systems. 21 CFR Part 11 is a US federal regulation that defines what is required for electronic records and signatures. They are complementary — GAMP 5 provides the methodology to meet 21 CFR Part 11 requirements.

What changed in the GAMP 5 Second Edition?

The 2022 Second Edition introduced guidance on professional judgment in validation, cloud and SaaS validation, updated data integrity expectations (ALCOA++), and cybersecurity considerations. It also strengthened alignment with CSA principles.

What is the difference between GAMP 5 and CSA?

GAMP 5 is a guidance document covering the full system life cycle. Computer Software Assurance (CSA) is the FDA’s risk-based approach to software assurance. The GAMP 5 Second Edition aligns with CSA principles — both emphasize proportional, risk-based testing.

What is the GAMP 5 V-model?

The V-model maps development activities — from user requirements through design specifications — to corresponding qualification activities. It is a core framework within GAMP 5. It ensures traceability between specifications and test results.

What is the difference between GMP and GAMP?

GMP (Good Manufacturing Practice) is a set of regulations governing the quality of pharmaceutical manufacturing processes. GAMP (Good Automated Manufacturing Practice) is a set of guidelines specifically focused on validating automated and computerized systems used within GMP environments.

What is the difference between Category 4 and Category 5 software?

Category 4 software consists of commercial packages configured for a specific environment, with no custom code. Category 5 software is fully custom-built. Category 5 requires the most rigorous validation, including full development life cycle documentation and testing.

Who publishes GAMP 5?

ISPE (International Society for Pharmaceutical Engineering) publishes GAMP 5 through its GAMP Community of Practice (CoP). The CoP includes industry professionals, regulators, technology providers, and subject-matter experts who collaborate on the guide.

How Kneat supports your GAMP 5 validation strategy

Eight of the world’s top 10 biopharma companies use Kneat Gx to manage GxP-compliant validation workflows.

Kneat Gx simplifies validation — from document management and review to approval and testing execution — within a single digital platform. Kneat Gx supports risk-based, CSA-aligned validation workflows consistent with GAMP 5 Second Edition guidance.

Kneat Gx is a cloud-based digital validation platform. It generates automatic audit trails, supports online testing execution, centralizes document access across sites, and maintains a complete compliance record. The platform scales to support unlimited users, processes, protocols, and facilities.

Customers report a 60% cycle time reduction and a 50%+ cut in validation cycles. Teams also eliminate 46% of process steps and achieve an 88% URS approval cycle reduction.

Explore how Kneat supports computer system validation for life sciences companies, or Book a demo to see the platform in action.

GAMP 5 will continue to evolve alongside the technologies it governs. Organizations that embed its principles today build a validation foundation ready for continued industry change.

Written By

Ben Finnan

Senior Manager of Brand and Content Marketing

Since 2018, he has been producing highly specialized content on digital validation, helping life sciences professionals navigate the transition to paperless validation. A seasoned B2B SaaS marketing leader, Ben leverages expertise in content strategy, brand development, and demand generation to drive Kneat’s global presence and support the industry’s adoption of digital validation best practices.

Revolutionize your validation

Digitalize validation your way, with the validation platform trusted by the world’s leading life sciences companies.

Book a demo