GAMP 5 in Pharma


GAMP 5 in Pharma – What It Really Is, Why FDA Loves It & How to Implement It Practically

My Quick Take: GAMP 5 is not a regulation. It’s a guideline – a guidebook written by ISPE to help us validate computerized systems in a simple, risk-based way. If 21 CFR Part 11 tells you WHAT to do, GAMP 5 tells you HOW to do it. Second edition came in July 2022 and now it is fully aligned with modern concepts like CSA, agile, SaaS, and cloud. If you are in QA, QC, IT, or Engineering, you must understand GAMP 5, otherwise CSV will always look complicated.
In this blog, I have explained:

  1. What is GAMP 5 in simple language
  2. Why GAMP 5 Second Edition (2022) is different from First Edition
  3. 5 Phases of GAMP 5 Lifecycle – With real example
  4. GAMP 5 Software Categories – Category 1 to 5 with pharma examples
  5. Risk-Based Validation & Relation with CSA
  6. How to write GAMP 5 documents practically

1. What is GAMP 5 in Simple Words?

Let me explain in natural way.

GAMP = Good Automated Manufacturing Practice. It is published by ISPE. Version 5 is the latest, second edition released in July 2022.

See, in pharma we have lot of computerized systems – HPLC software (Empower), LIMS, MES, SCADA, ERP (SAP), BMS, QMS software like Trackwise, even simple equipment like balances with software, autoclave with PLC, tablet compression with HMI.

Now FDA says in 21 CFR Part 11 and Annex 11 – you must validate these systems. But FDA never told HOW to validate. They just said validate as per risk.

So ISPE came with GAMP 5 to give us a framework. It is like a road map. It is not mandatory by law, but if you follow GAMP 5, FDA and EU auditors will be happy, because it is industry best practice. Almost all USFDA warning letters for CSV refer to GAMP 5 indirectly.

My analogy: If you want to go from Hyderabad to Mumbai, FDA says you must reach Mumbai safely. GAMP 5 is like Google Maps which shows you the best route, tolls, shortcuts, and risk areas. You can take other route also, but if you follow Google Maps, you will not get lost.

2. GAMP 5 Second Edition vs First Edition – What Changed in 2022?

First edition was in 2008. It was good but old. Second edition is completely updated for today’s technology.

Topic GAMP 5 First Edition (2008) GAMP 5 Second Edition (2022) – Current
Focus Heavy documentation, waterfall model Critical thinking, risk-based, less documentation if risk is low
CSA Alignment No CSA concept Fully aligned with FDA’s new CSA (Computer Software Assurance) draft 2022 – Focus on testing that matters
Agile & DevOps Not covered Added – Allows iterative development, sprint based validation
Cloud / SaaS / AI / ML No clear guidance Dedicated appendices – SaaS, Cloud (IaaS/PaaS), AI/ML, Blockchain, Open Source
Categories Cat 1-5, but Category 1 merged with 3 in practice Category 1 removed. Now only Cat 2,3,4,5. Cat 1 is considered as IT infrastructure.

My observation: Second edition is saying – Don’t do validation for the sake of paper. Think. Apply critical thinking. If a system is low risk (e.g., simple pH meter), do less testing. If high risk (e.g., MES that releases batch), do more testing. This is exactly what FDA CSA is also saying.

3. GAMP 5 Lifecycle – 5 Phases Explained with Real Example

GAMP 5 gives a V-model lifecycle. I will explain with example of LIMS implementation.

Phase 1: Concept & Planning
You decide we need LIMS for QC lab. Write Validation Plan, System Inventory, decide GxP impact. Is LIMS GxP? Yes, because QC data is GxP. So we need to validate. Create Supplier Assessment for LIMS vendor (e.g., LabVantage, Labware).

Phase 2: Project Phase – Specification
This is left side of V. You write URS (User Requirement Specification) – e.g., LIMS must have audit trail, must calculate assay, must integrate with Empower. Then vendor makes FS (Functional Spec) and DS (Design Spec). Traceability starts.

Phase 3: Project Phase – Configuration & Coding
Vendor configures LIMS. If custom code needed (Category 5), coding is done. For Category 4 (configurable), you do configuration, not coding.

Phase 4: Project Phase – Verification (Right side of V)
You test: IQ – Is LIMS installed correctly on server? OQ – Does login work? Does audit trail capture old/new value? PQ – Can QC analyst actually release sample in LIMS from start to end with real workflow? Also write SOPs, training.

Phase 5: Operation & Retirement
Go live. Then periodic review, change control, backup, incident management. After 10 years, retirement plan – How to migrate data. This phase is longest.

Key Document: Traceability Matrix (URS to OQ/PQ) – This is heart of GAMP 5. Auditor first asks for this.

4. GAMP 5 Software Categories – This is Most Important for Interview

Second edition has 4 categories now. I am giving you with pharma examples:

Category What It Means Pharma Example Validation Effort
Cat 1 – Infrastructure Software Operating systems, databases, network – Not application itself Windows Server, Oracle DB, Active Directory, VMware Low – Qualify infrastructure, backup
Cat 3 – Non-Configurable (COTS) Off-the-shelf, no configuration, use as is Simple HPLC firmware, weighing balance firmware, pH meter, MS Office (if not configured for GxP) Low – Record version, do risk assessment, one URS+IQ/OQ enough
Cat 4 – Configurable Product COTS but you configure as per your process – No custom code Empower, LIMS, MES (Werum PAS-X), Trackwise QMS, SAP EWM, SCADA, DCS, LMS, eQMS Veeva Vault Medium-High – 80% of pharma systems are Cat 4. Need full lifecycle URS, FS, Risk, IQ/OQ/PQ
Cat 5 – Custom Application Custom built for you, coding involved In-house built LIMS module in Excel VBA with macros, custom MES interface, AI/ML model built for OOS prediction, RPA bot for lab Highest – Need full SDLC, code review, more testing, more documentation

Practical Tip from me: When you get a system, first decide category. 90% mistakes happen here. Example – Empower is Cat 4, not Cat 3. Because you configure methods, custom fields, security. So you need more testing. Many companies still treat Empower as Cat 3 and get FDA 483.

5. Risk-Based Validation & CSA – Heart of GAMP 5 Second Edition

Old approach: Test everything equally, write 200 page OQ.

New GAMP 5 + CSA approach: Think about patient risk.

How to do risk assessment as per GAMP 5:

  • Step 1: List all requirements from URS.
  • Step 2: For each requirement, ask – If this fails, what is impact on Product Quality, Patient Safety, Data Integrity?
  • Step 3: Assign Risk – High, Medium, Low. Example – LIMS audit trail failure = High risk (Data Integrity). LIMS font color change = Low risk.
  • Step 4: High risk = Test thoroughly (scripted OQ). Low risk = Leverage vendor testing, or do informal testing, no need for detailed script.

This saves time. FDA also says same in CSA guidance – Don’t waste time testing printer icon. Focus on features that impact product quality.

6. How to Implement GAMP 5 Documents Practically – My Checklist

I have validated 30+ systems. My simple checklist for any system:

1. Validation Plan (VP) – One page – What, Why, Who, When
2. URS – What user wants – Write in clear language – “System must have audit trail with old value, new value, reason, timestamp, user ID per 21 CFR Part 11” – Not vague
3. Risk Assessment (RA) – Use GAMP 5 FMEA or simple matrix
4. Supplier Assessment – Is vendor mature? ISO 9001? Check audit report
5. Configuration Spec / Design Spec – For Cat 4/5
6. IQ/OQ/PQ Protocols – IQ – Installation, OQ – Functional testing per risk, PQ – Business process testing
7. Traceability Matrix – URS ID to Test ID – Auditor’s favorite
8. Validation Summary Report (VSR)
9. SOPs – User SOP, Admin SOP, Backup SOP, Periodic Review SOP

7. Common Mistakes Companies Do in GAMP 5

  1. Treating all systems as Category 5 – Wasting time and money
  2. Writing URS after purchase – URS should come BEFORE purchase, otherwise you justify what you already bought
  3. No traceability – URS says audit trail required but no test for audit trail in OQ – Direct 483
  4. Validating IT infrastructure (Windows) like application – Over-validation
  5. Ignoring second edition updates – Still following 2008 approach – No critical thinking
  6. Excel sheets considered Cat 3 – No, Excel with VBA is Cat 5 – Needs highest validation. Many companies fail here.

Final Words from Me

GAMP 5 is not to create more paper. It is to create confidence that your computerized system will work consistently and will protect patient and data. Second edition has made it more practical, more risk-based, and more aligned with cloud, SaaS, agile world.

If you are starting CSV, start with understanding categories. Once category is clear, half work is done.

I will be publishing detailed blogs on each category with templates – Empower validation (Cat 4), LIMS validation (Cat 4), and Excel VBA validation (Cat 5). Stay connected on PharmaShare.in

– Mahummed Asif
Helping pharma professionals understand validation in simple language


Disclaimer

This blog is written for educational purpose based on ISPE GAMP 5 Second Edition (July 2022), FDA 21 CFR Part 11, EU Annex 11, and FDA CSA Guidance 2022. This is not official ISPE document. Please refer to original ISPE GAMP 5 guide for official details.

Mahummed Asif - Pharma QA Expert

About the Author

Mahummed Asif is a experienced pharmaceutical Quality Assurance professional and publisher of Pharmashare. He has worked with leading Pharmaceutical organizations and has developed extensive expertise in Quality Assurance, deviation management, investigations, CAPA, QMS, Product Life Cycle Management, change control, risk management, validation, product complaints, product recalls, and regulatory compliance. He is passionate about sharing practical pharmaceutical knowledge with professionals, students, and quality practitioners across the industry.

Leave a Comment