GAMP 5 in Pharma – What It Really Is, Why FDA Loves It & How to Implement It Practically
- What is GAMP 5 in simple language
- Why GAMP 5 Second Edition (2022) is different from First Edition
- 5 Phases of GAMP 5 Lifecycle – With real example
- GAMP 5 Software Categories – Category 1 to 5 with pharma examples
- Risk-Based Validation & Relation with CSA
- How to write GAMP 5 documents practically
1. What is GAMP 5 in Simple Words?
Let me explain in natural way.
GAMP = Good Automated Manufacturing Practice. It is published by ISPE. Version 5 is the latest, second edition released in July 2022.
See, in pharma we have lot of computerized systems – HPLC software (Empower), LIMS, MES, SCADA, ERP (SAP), BMS, QMS software like Trackwise, even simple equipment like balances with software, autoclave with PLC, tablet compression with HMI.
Now FDA says in 21 CFR Part 11 and Annex 11 – you must validate these systems. But FDA never told HOW to validate. They just said validate as per risk.
So ISPE came with GAMP 5 to give us a framework. It is like a road map. It is not mandatory by law, but if you follow GAMP 5, FDA and EU auditors will be happy, because it is industry best practice. Almost all USFDA warning letters for CSV refer to GAMP 5 indirectly.
My analogy: If you want to go from Hyderabad to Mumbai, FDA says you must reach Mumbai safely. GAMP 5 is like Google Maps which shows you the best route, tolls, shortcuts, and risk areas. You can take other route also, but if you follow Google Maps, you will not get lost.
2. GAMP 5 Second Edition vs First Edition – What Changed in 2022?
First edition was in 2008. It was good but old. Second edition is completely updated for today’s technology.
| Topic | GAMP 5 First Edition (2008) | GAMP 5 Second Edition (2022) – Current |
|---|---|---|
| Focus | Heavy documentation, waterfall model | Critical thinking, risk-based, less documentation if risk is low |
| CSA Alignment | No CSA concept | Fully aligned with FDA’s new CSA (Computer Software Assurance) draft 2022 – Focus on testing that matters |
| Agile & DevOps | Not covered | Added – Allows iterative development, sprint based validation |
| Cloud / SaaS / AI / ML | No clear guidance | Dedicated appendices – SaaS, Cloud (IaaS/PaaS), AI/ML, Blockchain, Open Source |
| Categories | Cat 1-5, but Category 1 merged with 3 in practice | Category 1 removed. Now only Cat 2,3,4,5. Cat 1 is considered as IT infrastructure. |
My observation: Second edition is saying – Don’t do validation for the sake of paper. Think. Apply critical thinking. If a system is low risk (e.g., simple pH meter), do less testing. If high risk (e.g., MES that releases batch), do more testing. This is exactly what FDA CSA is also saying.
3. GAMP 5 Lifecycle – 5 Phases Explained with Real Example
GAMP 5 gives a V-model lifecycle. I will explain with example of LIMS implementation.
Phase 1: Concept & Planning
You decide we need LIMS for QC lab. Write Validation Plan, System Inventory, decide GxP impact. Is LIMS GxP? Yes, because QC data is GxP. So we need to validate. Create Supplier Assessment for LIMS vendor (e.g., LabVantage, Labware).
Phase 2: Project Phase – Specification
This is left side of V. You write URS (User Requirement Specification) – e.g., LIMS must have audit trail, must calculate assay, must integrate with Empower. Then vendor makes FS (Functional Spec) and DS (Design Spec). Traceability starts.
Phase 3: Project Phase – Configuration & Coding
Vendor configures LIMS. If custom code needed (Category 5), coding is done. For Category 4 (configurable), you do configuration, not coding.
Phase 4: Project Phase – Verification (Right side of V)
You test: IQ – Is LIMS installed correctly on server? OQ – Does login work? Does audit trail capture old/new value? PQ – Can QC analyst actually release sample in LIMS from start to end with real workflow? Also write SOPs, training.
Phase 5: Operation & Retirement
Go live. Then periodic review, change control, backup, incident management. After 10 years, retirement plan – How to migrate data. This phase is longest.
Key Document: Traceability Matrix (URS to OQ/PQ) – This is heart of GAMP 5. Auditor first asks for this.
4. GAMP 5 Software Categories – This is Most Important for Interview
Second edition has 4 categories now. I am giving you with pharma examples:
| Category | What It Means | Pharma Example | Validation Effort |
|---|---|---|---|
| Cat 1 – Infrastructure Software | Operating systems, databases, network – Not application itself | Windows Server, Oracle DB, Active Directory, VMware | Low – Qualify infrastructure, backup |
| Cat 3 – Non-Configurable (COTS) | Off-the-shelf, no configuration, use as is | Simple HPLC firmware, weighing balance firmware, pH meter, MS Office (if not configured for GxP) | Low – Record version, do risk assessment, one URS+IQ/OQ enough |
| Cat 4 – Configurable Product | COTS but you configure as per your process – No custom code | Empower, LIMS, MES (Werum PAS-X), Trackwise QMS, SAP EWM, SCADA, DCS, LMS, eQMS Veeva Vault | Medium-High – 80% of pharma systems are Cat 4. Need full lifecycle URS, FS, Risk, IQ/OQ/PQ |
| Cat 5 – Custom Application | Custom built for you, coding involved | In-house built LIMS module in Excel VBA with macros, custom MES interface, AI/ML model built for OOS prediction, RPA bot for lab | Highest – Need full SDLC, code review, more testing, more documentation |
Practical Tip from me: When you get a system, first decide category. 90% mistakes happen here. Example – Empower is Cat 4, not Cat 3. Because you configure methods, custom fields, security. So you need more testing. Many companies still treat Empower as Cat 3 and get FDA 483.
5. Risk-Based Validation & CSA – Heart of GAMP 5 Second Edition
Old approach: Test everything equally, write 200 page OQ.
New GAMP 5 + CSA approach: Think about patient risk.
How to do risk assessment as per GAMP 5:
- Step 1: List all requirements from URS.
- Step 2: For each requirement, ask – If this fails, what is impact on Product Quality, Patient Safety, Data Integrity?
- Step 3: Assign Risk – High, Medium, Low. Example – LIMS audit trail failure = High risk (Data Integrity). LIMS font color change = Low risk.
- Step 4: High risk = Test thoroughly (scripted OQ). Low risk = Leverage vendor testing, or do informal testing, no need for detailed script.
This saves time. FDA also says same in CSA guidance – Don’t waste time testing printer icon. Focus on features that impact product quality.
6. How to Implement GAMP 5 Documents Practically – My Checklist
I have validated 30+ systems. My simple checklist for any system:
2. URS – What user wants – Write in clear language – “System must have audit trail with old value, new value, reason, timestamp, user ID per 21 CFR Part 11” – Not vague
3. Risk Assessment (RA) – Use GAMP 5 FMEA or simple matrix
4. Supplier Assessment – Is vendor mature? ISO 9001? Check audit report
5. Configuration Spec / Design Spec – For Cat 4/5
6. IQ/OQ/PQ Protocols – IQ – Installation, OQ – Functional testing per risk, PQ – Business process testing
7. Traceability Matrix – URS ID to Test ID – Auditor’s favorite
8. Validation Summary Report (VSR)
9. SOPs – User SOP, Admin SOP, Backup SOP, Periodic Review SOP
7. Common Mistakes Companies Do in GAMP 5
- Treating all systems as Category 5 – Wasting time and money
- Writing URS after purchase – URS should come BEFORE purchase, otherwise you justify what you already bought
- No traceability – URS says audit trail required but no test for audit trail in OQ – Direct 483
- Validating IT infrastructure (Windows) like application – Over-validation
- Ignoring second edition updates – Still following 2008 approach – No critical thinking
- Excel sheets considered Cat 3 – No, Excel with VBA is Cat 5 – Needs highest validation. Many companies fail here.
Final Words from Me
GAMP 5 is not to create more paper. It is to create confidence that your computerized system will work consistently and will protect patient and data. Second edition has made it more practical, more risk-based, and more aligned with cloud, SaaS, agile world.
If you are starting CSV, start with understanding categories. Once category is clear, half work is done.
I will be publishing detailed blogs on each category with templates – Empower validation (Cat 4), LIMS validation (Cat 4), and Excel VBA validation (Cat 5). Stay connected on PharmaShare.in
– Mahummed Asif
Helping pharma professionals understand validation in simple language
Disclaimer
This blog is written for educational purpose based on ISPE GAMP 5 Second Edition (July 2022), FDA 21 CFR Part 11, EU Annex 11, and FDA CSA Guidance 2022. This is not official ISPE document. Please refer to original ISPE GAMP 5 guide for official details.
About the Author
Mahummed Asif is a experienced pharmaceutical Quality Assurance professional and publisher of Pharmashare. He has worked with leading Pharmaceutical organizations and has developed extensive expertise in Quality Assurance, deviation management, investigations, CAPA, QMS, Product Life Cycle Management, change control, risk management, validation, product complaints, product recalls, and regulatory compliance. He is passionate about sharing practical pharmaceutical knowledge with professionals, students, and quality practitioners across the industry.