GAMP 5 - Good Automated Manufacturing Practice
GAMP 5: V-Model Lifecycle and Specification Documents (URS, FS, DS, IQ, OQ, PQ)

GAMP 5 - Good Automated Manufacturing Practice GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ: V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability

V-Model Lifecycle - specification phases mirrored by verification phases. SPECIFICATION SIDE: (a) USER REQUIREMENTS SPECIFICATION (URS) - what the business needs the system to do + GxP requirements + regulatory + audit + user-defined functional + non-functional; (b) FUNCTIONAL SPECIFICATION (FS) - what the system does to meet URS; (c) DESIGN SPECIFICATION (DS) - how the system is designed + architecture + data flows + interfaces. VERIFICATION SIDE: (a) INSTALLATION QUALIFICATION (IQ) - verifies system installed per design; (b) OPERATIONAL QUALIFICATION (OQ) - verifies system operates per functional specification under simulated operating conditions; (c) PERFORMANCE QUALIFICATION (PQ) - verifies system performs per URS under actual operating conditions including throughput + reliability + business processes; (d) USER ACCEPTANCE TESTING (UAT) overlapping PQ. TRACEABILITY MATRIX: links URS requirements to FS/DS + test cases + test results + ensures coverage + supports inspection + change-impact analysis. RISK-PROPORTIONATE: high-risk requirements receive more verification depth + redundancy + independent verification; low-risk requirements may receive lighter touch + sampling. RE-USE: across similar systems + leverage prior validation knowledge.

What else in your programme already covers this

This control maps to 125 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • FFIEC-05 Roles and responsibilities definition

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

MITRE D3FEND · 1 control

  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

OWASP Top 10:2025 · 1 control

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.