ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems
GAMP 5 (Good Automated Manufacturing Practice, 2nd Edition 2022) is an industry guideline published by ISPE (International Society for Pharmaceutical Engineering). It provides a risk-based approach to the validation and management of computerised systems in the regulated life sciences industry. GAMP 5 is the de facto standard for computerised system validation (CSV) globally. The 2022 revision introduces Critical Thinking and simplifies approaches for modern systems including cloud, SaaS, and AI/ML. Covers the complete system lifecycle and applies to GMP, GLP, GCP, and pharmacovigilance.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (21)
Access Control
| Code | Title |
|---|---|
| GAMP5-SEC-14 | Logical Security and Access Management |
Change Management
| Code | Title |
|---|---|
| GAMP5-CHG-12 | Change Control and Periodic Review |
Cloud Compliance
| Code | Title |
|---|---|
| GAMP5-CLD-10 | Cloud and Software as a Service GxP Controls |
Configuration Management
| Code | Title |
|---|---|
| GAMP5-CFG-05 | Configuration and Design Control |
Data Integrity
| Code | Title |
|---|---|
| GAMP5-DI-07 | Data Integrity by Design (ALCOA+) |
Documentation
| Code | Title |
|---|---|
| GAMP5-DOC-17 | Documentation Management and Critical Thinking |
Emerging Technology
| Code | Title |
|---|---|
| GAMP5-AI-08 | AI and Machine Learning System Controls |
Infrastructure
| Code | Title |
|---|---|
| GAMP5-INF-09 | IT Infrastructure Qualification |
Key Concepts and Life Cycle
| Code | Title |
|---|---|
| GAMP5-KC-1 | Risk-Based Approach |
| GAMP5-KC-2 | Computerized System Life Cycle |
| GAMP5-KC-3 | Critical Thinking |
Lifecycle Management
| Code | Title |
|---|---|
| GAMP5-LC-01 | Computerised System Lifecycle Framework |
Operation and Data Integrity
| Code | Title |
|---|---|
| GAMP5-OP-1 | Operational Management |
| GAMP5-OP-2 | Data Integrity (ALCOA+) |
| GAMP5-OP-3 | Retirement and Migration |
Operations
| Code | Title |
|---|---|
| GAMP5-OPS-11 | Operational Phase Controls |
Records Management
| Code | Title |
|---|---|
| GAMP5-BU-15 | Backup, Archive, and Restoration |
Resilience
| Code | Title |
|---|---|
| GAMP5-BCP-13 | Business Continuity and Disaster Recovery |
Retirement
| Code | Title |
|---|---|
| GAMP5-DEC-16 | System Retirement and Decommissioning |
Risk Management
| Code | Title |
|---|---|
| GAMP5-QRM-02 | Quality Risk Management Across the Lifecycle |
Software Categories
| Code | Title |
|---|---|
| GAMP5-2.1 | Category 1: Infrastructure Software |
| GAMP5-2.3 | Category 3: Non-Configured Software |
| GAMP5-2.4 | Category 4: Configured Software |
| GAMP5-2.5 | Category 5: Custom Software |
| GAMP5-CAT-1 | Category 1 - Infrastructure Software |
| GAMP5-CAT-3 | Category 3 - Non-Configured Products |
| GAMP5-CAT-4 | Category 4 - Configured Products |
| GAMP5-CAT-5 | Category 5 - Custom Applications |
Specification
| Code | Title |
|---|---|
| GAMP5-REQ-04 | User Requirements and Specifications |
Specification and Verification
| Code | Title |
|---|---|
| GAMP5-SV-1 | User Requirements Specification (URS) |
| GAMP5-SV-2 | Functional Specification (FS) |
| GAMP5-SV-3 | Verification and Testing |
Supplier Management
| Code | Title |
|---|---|
| GAMP5-SUP-03 | Supplier Assessment and Leverage |
Verification and Testing
| Code | Title |
|---|---|
| GAMP5-TST-06 | Risk Based Testing and Verification |
Your Compliance Coverage
If you comply with ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems, you already cover:
FAA Cybersecurity Framework for Aviation
15%
5 controls mapped
Compare →NAIC Insurance Data Security Model Law (MDL-668)
15%
5 controls mapped
Compare →Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
15%
5 controls mapped
Compare →+ 494 more: Wisconsin Data Privacy Act (SB 670) (15%), Connecticut Data Privacy Act (CTDPA) (15%)
See all 497 mapped frameworks ↓Maps to 497 other frameworks
Frequently Asked Questions
What is ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems?
ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems is a compliance framework from International (ISPE) with 21 domains and 34 controls. GAMP 5 (Good Automated Manufacturing Practice, 2nd Edition 2022) is an industry guideline published by ISPE (International Society for Pharmaceutical Engineering). It provides a risk-based approach to the validation and management of computerised systems in the regulated life sciences industry. GAMP 5 is the de facto standard for computerised system validation (CSV) globally. The 2022 revision introduces Critical Thinking and simplifies approaches for modern systems including cloud, SaaS, and AI/ML. Covers the complete system lifecycle and applies to GMP, GLP, GCP, and pharmacovigilance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems have?
ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems has 34 controls organised across 21 domains. The largest domains are Software Categories (8 controls), Key Concepts and Life Cycle (3 controls), Operation and Data Integrity (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems map to?
ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems maps to 497 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (15% coverage), NAIC Insurance Data Security Model Law (MDL-668) (15% coverage), Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems compliance?
Start your ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerised Systems requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required