Glossary Term

GAMP 5

The industry framework regulators and QA teams use to scope computerized system validation.

GAMP 5 is the shared vocabulary of computerized system validation — when a vendor says 'Category 4' or an auditor asks for your lifecycle approach, this is the framework behind the words.

GAMP 5 software category classification diagram showing Categories 1 through 5 mapped to risk-based validation effort
On this page
  1. Definition
  2. Why It Matters
  3. Regulatory Context
  4. In Practice
  5. Key Controls
  6. Complere Approach
  7. Related Terms

What GAMP 5 is

GAMP 5A Risk-Based Approach to Compliant GxP Computerized Systems — is the industry guide published by ISPE (International Society for Pharmaceutical Engineering) that defines how regulated companies specify, validate, and maintain computerized systems. The current version is the second edition, published in July 2022; the first edition dates to 2008, and the GAMP framework itself goes back to the early 1990s.

Its core ideas: scale validation effort to risk, complexity, and novelty; leverage supplier activities and documentation instead of repeating them; apply critical thinking rather than templated test volume; and manage systems across their whole lifecycle — concept, project, operation, retirement — not just at go-live. The guide is supported by a family of GAMP Good Practice Guides on topics like data integrity, testing, and IT infrastructure.

Its best-known tool is the software category classification: Category 1 (infrastructure software), Category 3 (non-configured products), Category 4 (configured products), and Category 5 (custom applications) — Category 2 was retired with the first edition's hardware focus. The category signals how much specification and verification work the regulated company owes on top of what the supplier already did. A configured multi-tenant eQMS is typically assessed as Category 4.

Guidance, not law

GAMP 5 is not a regulation — no authority enforces it directly. It is the industry's consensus method for meeting the validation expectations that ARE law (21 CFR Part 11 §11.10(a), EU GMP Annex 11). Auditors use its vocabulary because everyone else does; a vendor claiming to be 'GAMP certified' is waving a flag that does not exist.

Why GAMP 5 dominates vendor qualification

When a quality team qualifies an eQMS, LIMS, or MES supplier, the assessment is almost always GAMP-shaped: what category is the system, what does the supplier's quality system cover, which lifecycle deliverables exist (URS, risk assessment, configuration specification, test evidence, traceability), and what residual work belongs to the regulated company. The framework gives both sides a shared map of who owes which evidence — which is why supplier assessments, audit agendas, and validation plans all speak its language.

The second edition (2022) matters because it modernized the framework for how software is actually built and run now: it embraces agile and incremental delivery, cloud services and SaaS, automated testing and tool-supported traceability, and gives explicit attention to data integrity, IT service management, and emerging tools. It aligns with the critical-thinking direction FDA later formalized in its Computer Software Assurance guidance. Validation positions written against the 2008 first edition tend to over-document and under-think — exactly what the second edition argues against.

For buyers, GAMP 5 fluency is also a vendor-quality signal: a supplier who can state their category honestly, show their lifecycle deliverables, and explain which V-model activities they perform versus which remain with the customer has done this before. One who answers "we are fully GAMP compliant" has not understood the question.

How GAMP 5 relates to the regulations

GAMP 5 is the how behind several regulatory whats:

  • 21 CFR Part 11 §11.10(a) — requires validation of systems handling electronic records; GAMP 5 supplies the lifecycle method most companies use to satisfy it
  • EU GMP Annex 11 — requires risk-based validation of computerised systems across their lifecycle, with supplier oversight; GAMP 5 is the de-facto interpretation most EU sites apply (and the 2025 draft Annex 11 revision moves even closer to GAMP-style lifecycle language)
  • FDA CSA Final Guidance (February 3, 2026) — FDA's risk-based assurance position for production and quality system software; directionally aligned with GAMP 5's critical-thinking principle, and the two are routinely applied together
  • ISO 13485 §4.1.6 / QMSR contexts — software used in the QMS must be validated for its intended use; GAMP categories scope that work for device manufacturers
  • EU GMP Annex 15 — qualification and validation generally; GAMP 5 details the computerized-system slice
  • ICH Q9(R1) — the quality risk management method that drives GAMP's risk-proportionate effort
  • GAMP Good Practice Guides — companion volumes (data integrity, testing, infrastructure) that auditors increasingly cite alongside the main guide

Using GAMP 5 without drowning in paper

The practical failure mode with GAMP 5 is treating it as a template library: generating maximum documentation for every system regardless of risk. The framework itself says the opposite — a Category 4 configured product with a qualified supplier should lean on supplier evidence, focus testing on the regulated company's configuration and intended use, and document decisions rather than boilerplate.

A workable pattern for an eQMS or similar Category 4 system: classify honestly (configured product — unless you have commissioned custom code, which moves those parts to Category 5); assess the supplier once and deeply — their quality system, lifecycle deliverables, testing and release discipline, change management — and record what you will leverage; write a URS that reflects your intended use, not the vendor's feature list; risk-assess per requirement so high-impact functions (e-signatures, audit trail, record lifecycle) get scripted depth and low-impact configuration gets lighter verification; and keep the lifecycle alive — supplier releases, configuration changes, and periodic review all feed back into the validated state.

The second edition's additions matter most in operation: for SaaS, the supplier releases on their cadence, so your change-evaluation and regression-evidence process is the real control; tool-supported traceability (requirements-to-test linkage in systems rather than spreadsheets) is explicitly endorsed; and critical thinking is expected to show up as documented rationale — why this depth, why this sample, why this residual risk is acceptable.

What a defensible GAMP 5 position contains

Whether you are the regulated company or assessing a vendor, these are the concrete artifacts a GAMP-shaped review looks for:

The category 4/5 boundary

The most consequential classification call is Category 4 versus 5. Configuration uses the product's intended mechanisms (settings, workflows, fields); customization is new code. Custom scripts, bespoke integrations, and modified vendor code are Category 5 work hiding inside a Category 4 system — and inspectors know to ask.

  • System inventory with categories — every GxP computerized system classified, with the rationale recorded
  • Documented supplier assessment — quality system, lifecycle deliverables, testing/release discipline; refreshed on a defined cadence
  • Intended-use URS — requirements with unique IDs, written against your processes, not the brochure
  • Per-requirement risk assessment — severity/impact-driven tiers that visibly drive test depth
  • Traceability — URS to risk to test to result, maintainable (tool-supported beats spreadsheet)
  • Leverage statement — what supplier evidence you rely on and why it is trustworthy
  • Configuration specification — your settings, roles, and workflows recorded as the validated baseline
  • Change and release evaluation — how vendor releases and configuration changes are assessed against the validated state
  • Periodic review — scheduled confirmation that the system still operates in a validated state, with records
  • Documented critical thinking — rationale for depth decisions, not just the outputs

How Complere positions against GAMP 5

Complere is assessed as a GAMP 5 Category 4 configured product, and the validation pack exists so that a GAMP-shaped supplier assessment finds what it is looking for without a negotiation.

The lifecycle deliverables ship per module, generated against the customer tenant: Validation Master Plan, User Requirements Specification, Risk Assessment with per-requirement tiers, Traceability Matrix linking requirements to risk to test cases, IQ/OQ/PQ protocols, a 21 CFR Part 11 checklist, and an Audit Trail Specification. Validation depth is scoped per requirement risk in line with FDA's CSA guidance — high-risk requirements carry scripted test depth, lower-risk configuration carries lighter qualification, and the rationale is recorded the way GAMP's critical-thinking principle expects.

The leverage model is explicit: Complere performs and documents the product-level lifecycle work — requirements, testing, release discipline, change management — and the customer's residual work concentrates on intended use: their configuration, their workflows, their PQ in their tenant. On releases that affect validated functionality, release notes map changes to affected requirements and only the affected evidence regenerates, which is the SaaS lifecycle behaviour the second edition asks suppliers to support.

What stays with your team is the regulated company's share of the framework: your system inventory and classification decision, your supplier assessment of us (we expect it — the artifacts above are its inputs), your intended-use URS choices, and your periodic review. The category model is explained further in the GAMP 5 categories guide, the methodology in the validation approach, and the artifact list on the validation pack page.

Frequently asked questions

Common questions about GAMP 5 sourced from regulatory references and inspection patterns.

Is GAMP 5 mandatory?

No — GAMP 5 is industry guidance from ISPE, not a regulation. What is mandatory is validation itself (21 CFR Part 11 §11.10(a), EU GMP Annex 11). GAMP 5 is the consensus method most regulated companies and auditors use to meet those requirements, which is why supplier assessments speak its vocabulary.

What GAMP 5 category is an eQMS?

A configured commercial eQMS is typically Category 4 (configured products): the supplier builds and tests the product, and the regulated company specifies, configures, and verifies its own intended use on top. Custom-developed extensions would be assessed as Category 5.

What changed in the GAMP 5 second edition?

The 2022 second edition modernized the framework for current software practice: agile and incremental delivery, cloud and SaaS, automated testing and tool-based traceability, stronger emphasis on critical thinking over document volume, and closer alignment with the risk-based direction FDA formalized in its Computer Software Assurance guidance.

How do GAMP 5 and CSA relate?

They point the same way. GAMP 5 (second edition) and FDA's CSA Final Guidance (February 3, 2026) both argue for scaling assurance effort to risk and intended use rather than generating uniform documentation. GAMP 5 covers the full lifecycle method; CSA is FDA's position on assurance for production and quality system software.

What is the difference between GAMP Category 4 and Category 5?

Category 4 is configured products - you use the product's intended configuration mechanisms (settings, workflows, fields, roles). Category 5 is custom applications - new code written for you. Custom scripts, bespoke integrations, and modified vendor code are Category 5 work that often hides inside an otherwise Category 4 system, and they carry more validation responsibility. Classify honestly: inspectors know to ask where the custom code is.

About the author

Complere Reference Team

Compliance and quality-systems specialists maintaining the Complere glossary for regulated quality, validation, and inspection-readiness teams. Entries are reviewed against current FDA, MHRA, EMA, ICH, and PIC/S guidance.

Continue Exploring

Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

GAMP 5 categories guide
Related

GAMP 5 Categories Guide

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Validation approach
Related

Validation Approach

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Validation pack
Related

Validation Pack

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore

See a GAMP 5 Category 4 validation pack in practice

Walk through the modules and workflows that address this area inside a controlled, validation-ready quality system.