# ISPE GAMP 5 Compliance

Customer & Industry Requirements

###### Good Automated Manufacturing Practice 5 — Second Edition (ISPE)

## The FDA Finalized CSA Guidance. The EU Is Revising Annex 11. Do You Know Which Systems in Your Supply Chain Meet GAMP 5 Compliance Standards?

GAMP 5 compliance demands risk-based validation evidence across every computerized system in your manufacturing and quality environment—with audit trails, lifecycle documentation, and supplier qualification records for every software category. The Second Edition now covers cloud, AI/ML, and agile development. FDA and EMA inspectors cite computerized system deficiencies in 30–35% of GMP findings.

Certivo automates supplier validation evidence collection from system qualification through audit-ready documentation.

## Regulation Overview

- **Jurisdiction:** Global (adopted under FDA, EMA, PIC/S, and ICH-aligned regulatory frameworks)
- **Regulatory Body:** International Society for Pharmaceutical Engineering (ISPE)
- **Regulation Number:** ISPE GAMP 5 — Second Edition (2022)
- **Effective Date:** Original: March 2008; Second Edition: July 2022
- **Official Source:** [ispe.org/publications/guidance-documents/gamp-5](https://ispe.org/publications/guidance-documents/gamp-5)
- **Key Threshold:** Risk-based validation scaled to software category and process impact

# What Is GAMP 5?

GAMP 5 is ISPE's globally recognized guideline for validating computerized systems in pharmaceutical and regulated manufacturing environments. For supply chain and quality teams, the core obligation is ensuring every automated system affecting product quality, patient safety, or data integrity is validated proportionally to its risk—with full lifecycle documentation from initial qualification through retirement.

The Second Edition (2022) expanded coverage to cloud computing, AI/ML, agile development, and supplier ecosystem management. FDA's finalized Computer Software Assurance guidance (September 2025) formally endorses the risk-based validation approach GAMP 5 has advocated for years. The EU's draft revision of Annex 11, expected to finalize mid-2026, aligns directly with GAMP 5 principles.

GAMP 5 compliance requires category-specific validation documentation—user requirements, risk assessments, IQ/OQ/PQ protocols, and audit trails—from every system supplier and integrator.

## Key Components / Sub-Frameworks

### Obligation 
- Configuration baseline documentation and change control

#### Software Category 1
- Infrastructure software (OS, databases, network tools)

### Obligation
- Functional testing, vendor qualification, installation verification

#### Software Category 3
- Non-configurable COTS software

### Obligation
- Full IQ/OQ/PQ on configuration; risk-based testing of workflows

#### Software Category 4
- Configurable software (ERP, LIMS, QMS, MES)

### Obligation
- Full SDLC documentation, source code review, comprehensive IQ/OQ/PQ

#### Software Category 5
- Custom/bespoke software

### Obligation
- Requirements traceability matrix linking URS to test protocols

### V-Model Lifecycle
- Specification-to-verification traceability

### Obligation
- Audit rights, quality agreements, development lifecycle evidence

### Supplier Assessment
- Vendor qualification and ongoing oversight

## Key Compliance Requirements

# Who Must Comply
- Pharmaceutical and biotech manufacturers operating computerized systems under GMP
- Medical device manufacturers subject to FDA 21 CFR Part 820 and ISO 13485
- Contract manufacturers (CMOs/CDMOs) processing GxP data on behalf of sponsors
- Equipment and software suppliers providing systems used in GMP environments
- Laboratories using LIMS, chromatography data systems, or ELNs under GLP/GMP
- Companies deploying cloud, SaaS, or AI-based tools in production or quality operations

## Key Thresholds

#### Category 4/5 Systems
- Full IQ/OQ/PQ validation with risk-justified testing scope

#### High Process Risk Functions
- Rigorous scripted or hybrid testing per FDA CSA framework

#### 21 CFR Part 11
- Electronic records and signatures require validated audit trails

#### ALCOA+ Principles
- All GxP data must be Attributable, Legible, Contemporaneous, Original, Accurate

## Core Obligations

1. **System Validation**  
   Validate all GxP computerized systems before use per GAMP 5 risk-based approach  
   **DEADLINE:** Prior to system go-live

2. **Lifecycle Documentation**  
   Maintain URS, risk assessments, configuration specs, and test protocols  
   **DEADLINE:** Continuous throughout system lifecycle

3. **Audit Trail Controls**  
   Implement secure, immutable audit trails with periodic review procedures  
   **DEADLINE:** Ongoing; inspected at every GMP audit

4. **Supplier Qualification**  
   Qualify software vendors through documented assessment of development practices  
   **DEADLINE:** At procurement and periodically thereafter

5. **Change Control**  
   Assess impact of every system change on validated state and data integrity  
   **DEADLINE:** Per change, with documented risk evaluation

## Certivo in Action

### Certivo in Action—GAMP 5 Workflow

GET EVIDENCE IN

Collect Validation Documentation from Every System Supplier—Without the Chasing

CORA launches targeted campaigns to collect GAMP 5 validation evidence from software vendors, equipment suppliers, and system integrators—following up automatically and accepting documentation in any format.

- Launch validation evidence campaigns to hundreds of suppliers with one click  
- CORA-powered outreach in suppliers' native languages  
- Accept any format: PDFs, Excel validation matrices, IQ/OQ/PQ protocols, vendor audit reports  
- Track response rates and escalate non-responders automatically

### MAKE SENSE OF IT

Know Instantly When Validation Documentation Falls Below GAMP 5 Requirements

CORA extracts every validation deliverable to requirement level, validates against GAMP 5 category-specific obligations, and flags documentation gaps automatically.

- CORA parses supplier packages to extract test protocols, risk assessments, and configuration evidence  
- Automatic validation against category-specific GAMP 5 requirements (Cat 1, 3, 4, 5)  
- Real-time alerts when regulatory updates affect your validated system portfolio  
- Gap analysis against FDA CSA and EU Annex 11 requirements

### PROVE COMPLIANCE OUT

Respond to Auditor Requests in Hours, Not Weeks

Generate audit-ready validation summary reports and system lifecycle documentation instantly from validated supplier evidence.

- One-click validation summary packages per GAMP 5 category  
- Pre-formatted audit trail review documentation for GMP inspections  
- Auditor-specific templates with full traceability from URS to test evidence  
- Complete audit trail for every validation assessment and supplier qualification

## Features Tabs

### Declaration Collection

Certivo's automated campaigns achieve 95% response rates vs. 20–30% with manual outreach.

- Targeted campaigns by system category, supplier tier, or validation scope  
- Multi-language outreach in suppliers' native languages  
- Intelligent follow-up sequences adapting to supplier behavior  
- Format-agnostic: PDFs, Excel, IQ/OQ/PQ protocols, vendor audit packages

### Validation Extraction

Every validation package parsed to requirement level automatically—no manual data entry.

- Deep extraction of test protocols, risk assessments, configuration specifications, and audit trail evidence  
- Parses IQ/OQ/PQ documentation, vendor validation summaries, and proprietary templates  
- Multi-language document processing  
- Anomaly detection for incomplete or inconsistent validation deliverables

### Regulatory Monitoring

Always validated against current FDA CSA, EU Annex 11, and GAMP 5 requirements—not your last audit.

- Automatic sync with FDA, EMA, and PIC/S regulatory updates throughout the year  
- Gap analysis per GAMP 5 category when new guidance is issued  
- Proactive alerts when regulatory changes affect your validated system portfolio  
- Historical tracking of validation status changes across system lifecycle

### Audit Response

Generate GAMP 5 validation summaries in hours instead of 4–6 weeks.

- One-click audit response packages with full validation documentation chain  
- System lifecycle summaries meeting FDA, EMA, and PIC/S inspection requirements  
- Supplier qualification chain with complete traceability  
- Deadline tracking for periodic review and revalidation cycles

### System Lifecycle Management

Pre-validated lifecycle documentation turns periodic review from burden to streamlined workflow.

- Centralized compliance data backbone for all computerized system records  
- Change control impact assessment with automated risk classification  
- Multi-system portfolio dashboards with validation status by category  
- Retirement documentation and data migration evidence tracking

## Related Regulations

- **FDA 21 CFR Part 11**  
  Electronic records and signatures; GAMP 5 provides the validation framework to meet Part 11 requirements

- **EU GMP Annex 11**  
  EU computerized systems requirements; draft revision (mid-2026) aligns directly with GAMP 5 principles

- **FDA CSA Guidance**  
  Risk-based software assurance finalized September 2025; complements GAMP 5 categorization

- **ICH Q9**  
  Quality risk management; foundational to GAMP 5's risk-based validation approach

- **ISO 13485**  
  Medical device QMS; now incorporated by reference into FDA QMSR (February 2026)

- **EU GMP Annex 22 (Draft)**  
  New AI governance annex; covers AI/ML systems in GMP environments

## Ready to Automate GAMP 5 Compliance?

See how Certivo's computerized system validation software transforms supplier qualification from reactive documentation scrambles to continuous compliance monitoring and audit readiness.
