GAMP 5 - Good Automated Manufacturing Practice
GAMP 5: 2nd Edition (2022) - AI/ML + Cloud + Agile + DevOps + Computer Software Assurance (CSA)

GAMP 5 - Good Automated Manufacturing Practice GAMP5-2nd-Edition-AI-Cloud-Agile-CSA: 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)

GAMP 5 2nd Edition (July 2022) key updates + FDA Computer Software Assurance (CSA) coordination. AI/ML SYSTEMS: dedicated guidance on validation of AI/ML in pharma (predictive maintenance + image analysis + drug discovery + clinical decision support); training + validation + retraining cycles + monitoring + bias detection + explainability + adaptive AI/ML controlled-change management; coordinated with FDA AI/ML Software as a Medical Device (SaMD) Action Plan + EU AI Act + IMDRF AI Working Group. CLOUD COMPUTING + SaaS: shared-responsibility model + supplier qualification + business continuity + data sovereignty + multi-tenant considerations + IaaS/PaaS/SaaS lifecycle differences; integrates with FedRAMP-like sector certifications + ISO 27001/27017/27018 + ISPE cloud guidance. AGILE + ITERATIVE DEVELOPMENT: scrum/kanban/SAFe adaptation; sprint-level documentation + risk assessment + acceptance criteria + lifecycle artifacts in sprint outputs; balance regulatory compliance with iterative speed. DEVOPS + CI/CD: automated testing + deployment pipelines + version control + infrastructure-as-code + automated validation; emphasis on test automation reducing manual qualification effort. FDA COMPUTER SOFTWARE ASSURANCE (CSA) - 2022 Draft Guidance: risk-based + critical-thinking-driven + assurance-by-assessment + reducing reliance on prescriptive testing for low-risk systems; coordinated with GAMP 5 critical-thinking emphasis. CRITICAL THINKING EMPHASIS: throughout 2nd Edition + replacing some prescriptive testing requirements with judgment-based assurance.

What else in your programme already covers this

This control maps to 53 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.5 Securely Dispose of Data
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • 3.5 Securely Dispose of Data
  • DIQ-1 Data Integration and Interoperability
  • A.1 Point-of-Care Testing Additional Requirements

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.