GAMP 5 Second Edition - QFINITY
QFINITY · ISPE GAMP

GAMP 5 Validation.

GAMP 5 validation follows the life cycle model: evidence is maintained across the entire system life cycle - from the concept decision to retirement - and does not end with the validation report. GAMP 5 is the definitive ISPE guide to GxP compliance and computerized systems - referenced by regulatory agencies and life science companies around the world. QFINITY was part of the Core Team behind the Second Edition and brings that expertise directly to every engagement.

The guide

The reference for computerized systems.

The GAMP 5 Guide offers a pragmatic, practical framework for delivering compliant computerized systems that are fit for their intended use - efficiently and effectively. Its flexible, risk-based approach, grounded in scalable specification and verification, has proven effective for systems of every size.

The Second Edition (July 2022) retains the principles and framework of the First Edition but has been updated and expanded to reflect the increasing importance of service providers, changing approaches to software development, and the widespread use of cloud technology, software tools, and automation.

GAMP 5 Second Edition stresses critical thinking by knowledgeable, experienced practitioners as the basis for the right validation approach. What the FDA formalized as Computer Software Assurance in 2025 was already methodically embedded here.
What's new

The focus areas of the Second Edition.

  • Critical thinking

    A stronger emphasis on critical thinking throughout the validation of computerized systems.

  • Artificial Intelligence & Machine Learning

    Validation of systems that use artificial intelligence and machine learning.

  • Agile software development

    Recognition of agile methods and iterative development in regulated environments.

  • IT Service Management & Cloud

    Expanded IT service management, covering cloud solutions up to and including SaaS.

  • Open-source software

    New guidance on using open-source components in regulated environments.

  • Blockchain

    New guidance for blockchain systems.

The approach

How does a GAMP 5 validation work?

A GAMP 5 validation follows the guide's life cycle model: four phases from the concept decision to retirement; the scope and depth of specification and verification scale with risk, complexity, and novelty.

PhaseWhat happens
ConceptNeed and Intended Use emerge from the business process; an initial risk assessment and the fundamental decision on solution path and supplier.
ProjectPlanning, specification, configuration or development, verification, and release - scaled by risk; supplier deliverables are assessed and leveraged rather than repeated.
OperationThe longest phase: change and configuration management, periodic review, and incident and CAPA processes maintain the validated state.
RetirementAn orderly exit: data migration or archiving in line with retention requirements - the records remain readable and available beyond the system's lifetime.

And the V-model? It is a specification-verification model: it shows which verification activity answers which level of specification - nothing more. It covers exactly one phase, the project; concept, operation, and retirement do not appear in it. The V-model sits inside the life cycle - it is not the life cycle. The guide itself drew that conclusion early: the First Edition (2008) already pulled back the classic V diagram, and the Second Edition carries the generic specification-verification representation consistently forward - too often the V had been misread as a linear waterfall, and the same logic carries iterative, agile approaches, just run incrementally.

What the system produces follows IT's oldest pattern: input - processing - output. A function turns input data into output data; the sum of the functions is the system. Its outputs are electronic records and signatures - subject to 21 CFR Part 11 and Annex 11, and their compliant creation is demonstrated as part of the validated system. Annex 11 sits in the GMP framework - the principle applies across the entire GxP spectrum; in clinical research, through ICH E6(R3) and the EMA guideline on computerised systems.

The V-model answers the question "What do I verify against?" - not the question "How does a system live - documented and demonstrable?"
Risk sets the depth

The risk process behind the evidence.

Within the phases, quality risk management governs what evidence is produced and how deep it goes. ICH Q9 defines the systematic process - GAMP 5 translates it into five steps for computerized systems:

  1. 1

    Initial risk assessment

    A first appraisal of the system in its process context: how does it influence GxP-relevant operations - and what is the system's overall impact level?

  2. 2

    Identify the relevant functions

    Which functions touch patient safety, product quality, or data integrity? Only they carry the risk - and only they earn the testing depth.

  3. 3

    Functional risk assessment & controls

    For each identified function: identify and assess failure scenarios and define controls - technical, procedural, or organizational.

  4. 4

    Implement & verify controls

    The controls are implemented and verifiably confirmed - traceable back to the requirement they protect.

  5. 5

    Review periodically

    Risks and controls are reassessed regularly in operation - the validated state is a maintained state, not an archived document.

The categories

Software categories: a continuum, not a checklist.

The GAMP categories sort software by its origin; behind them sit two causal drivers: novelty and complexity. The more individuality a regulated company demands, i.e. the further it departs from the software's standard, the less the supplier's assessable prior work carries - and the larger the company's own share of the evidence becomes.

CategoryWhat follows from it
1 - Infrastructure softwareoperating systems, databases, middlewareEstablished and widely deployed - low novelty. It is operated under control and qualified, not validated individually.
3 - Standard productsnon-configured, used "as supplied"The evidence rests on assessed supplier work: supplier assessment plus verification against your own requirements carry it.
4 - Configured productsLIMS, MES, eQMS, ERPThe configuration is the new, unproven part - the evidence concentrates on it and on the processes it supports.
5 - Custom applicationsbespoke development, custom codeMaximum novelty, no prior work for the evidence to lean on: the full life cycle evidence from specification to testing rests with the operator and its supplier.

The Second Edition spells out what practice often shortens: the categories are a continuum, not a grid - real systems mix components from several categories, and an MES carries parts of 3, 4, and 5 at once. And the category is only one scaling factor alongside GxP impact, complexity, and novelty. Reading it as a validation checklist means validating past the risk. A product's reach plays its own role: the more users a standard function has, the more the supplier itself has a stake in hardening that standard - a defect there is an immediate reputational hit. Yet only what exists as assessable supplier work can enter the evidence. Applied correctly, GAMP 5 is an efficiency program: verifiable requirements, risk-based decisions, leveraged supplier input, efficient testing, tools and automation - validation becomes effective and efficient because the effort lands where the risk is.

FAQ

Frequent questions about GAMP 5 validation.

No. Validation itself is required by the regulations - EU GMP Annex 11 and 21 CFR Part 11. GAMP 5 is not a regulation but the industry's established methodology for delivering that evidence risk-based. The FDA's CSA guidance, in its current revision (02/2026), names the Second Edition as one source of information on testing methods.

Risk-based rather than template-driven: alongside scripted testing, the Second Edition explicitly encourages exploratory and unscripted testing as well as test automation - and lets electronic records from tools take the place of formal test documents. The benchmark is demonstrable coverage of the risk-relevant requirements, not the form.

Yes - explicitly since the Second Edition: it takes medical device regulation into scope and addresses manufacturers' production and QMS systems. The First Edition had still excluded embedded medical device software.

No. Computer Software Assurance is the FDA's way of sharpening risk-based testing for the production and QMS software of medical device manufacturers - something the risk-based approach of GAMP 5 had already embedded methodically. The approach is followed well beyond that formal scope. GAMP 5 provides the life cycle, CSA sharpens the test strategy: not a replacement, but two perspectives on the same evidence. How closely the two converge shows in the announced GAMP Good Practice Guide "Testing of GxP Systems" (3rd Edition): created with members of the FDA CSA team contributing, it embeds the CSA mindset natively in the testing methodology - scaled by the system's complexity and novelty.

Contributor

QFINITY on the GAMP 5 Second Edition Core Team.

We are honored and proud to have served on the Core Team and helped create and review the guide - as a long-standing, active contributor to the ISPE GAMP Community. Our reading of the Second Edition appeared as an article in Pharm. Ind.

  • Contributed to the creation and review of GAMP 5 Second Edition
  • Frank Henrichmann: Chair of the GAMP Global Steering Committee
  • Oliver Herrmann: GAMP Track Lead, ISPE Europe Annual Conference 2026
  • Qualified ISPE GAMP trainers - a small circle worldwide
  • Contributed to the GPG "Enabling Innovation", which the Second Edition builds on
Frank Henrichmann and Oliver Herrmann pointing at their names on ISPE's GAMP 5 Second Edition contributor wall
First-hand

The guide the FDA itself points to.

QFINITY presented the Second Edition just months after its release, at the 15th official GAMP 5 conference in Mannheim (2022) - and knows the guide's principles first-hand. And it is the guide the FDA itself points to: in 2003, its Part 11 guidance named the GAMP 4 Guide as an industry reference for validation; the CSA guidance added the reference to the Second Edition for testing methods with its 02/2026 revision - neither the draft nor the initial final contained it.

Critical Thinking CSA AI / ML Agile Cloud / SaaS
More from our service areas

From the guide to everyday practice.

Let's talk about your validation.

We translate GAMP 5 Second Edition - risk-based CSV, Computer Software Assurance, AI/ML, agile, cloud/SaaS - into a concrete validation strategy for you. Your first consultation is free - about 30 minutes, directly with a contributor to the Core Team.

Book an intro call