GAMP 5 Second Edition: Key Changes and Their Implications
The second edition of GAMP 5 (2022) introduced significant updates to the framework for computer system validation in regulated environments. This article summarises the most important changes and their practical implications for organisations managing validation programmes.
Background: Why a Second Edition?
The first edition of GAMP 5 was published in 2008. In the fourteen years between editions, the pharmaceutical industry's technology landscape changed significantly: cloud computing and SaaS became mainstream, data integrity moved from a niche concern to a primary regulatory focus, and agile software development methodologies became common. The 2008 guidance did not adequately address these developments.
The second edition was also influenced by the recognition that many organisations had implemented GAMP 5 in a mechanistic way, producing prescribed documentation without exercising the critical judgement that the framework was intended to encourage. The second edition is more explicit about the need for professional judgement and the risk of over-documentation at the expense of genuine quality assurance.
Stronger Emphasis on Critical Thinking
The second edition places greater emphasis on the application of critical thinking throughout the validation lifecycle. Rather than following prescriptive validation steps, practitioners are expected to apply judgement, assessing what testing is genuinely necessary to provide assurance of fitness for purpose rather than executing standard test scripts to produce a validation record. This shift challenges organisations whose CSV programmes are driven by documentation production rather than risk-based assessment.
Revised Software Category Model
GAMP 5 Second Edition retains the software category model (Category 1 Infrastructure, Category 3 Non-Configured, Category 4 Configured, Category 5 Custom) but provides significantly more detailed guidance on applying it, particularly for modern software architectures including SaaS, cloud-hosted systems and hybrid deployments. The guidance clarifies that the category is a starting point for determining validation approach, not a fixed prescription, and that the risk profile of the specific use case should inform the validation strategy.
Cloud and SaaS Systems
The second edition provides dedicated guidance on cloud-hosted and SaaS systems, an area not adequately covered in the 2008 first edition. For SaaS systems where the software is not configurable and the user organisation has no control over the software code, the validation approach focuses on: supplier assessment (the GAMP Supplier Questionnaire approach), data integrity controls, qualification of interfaces, and business continuity arrangements. The concept of "fit for purpose testing" is central, testing that the system performs the GMP functions required in the specific regulated use context.
Data Integrity Integration
GAMP 5 Second Edition integrates data integrity considerations throughout the validation lifecycle rather than treating data integrity as a separate topic. Risk assessments must consider data integrity risks alongside process and product risks. Validation testing must include verification of ALCOA+ controls. Audit trail configuration, access controls and backup/recovery are treated as validation deliverables, not post-validation additions.
Lifecycle Approach and Periodic Review
The second edition strengthens the lifecycle emphasis, particularly the continuing validation phase. Periodic review is positioned as an essential element of maintaining validated status, not a box-ticking exercise. The guidance describes what a meaningful periodic review should examine: changes since last review, incidents and deviations, changes to the regulatory environment, changes to intended use. An annual summary statement that the system remains validated without substantive review of these elements does not satisfy the intent of the guidance.
Supplier Assessment Framework
GAMP 5 Second Edition provides an updated framework for supplier assessment, the process by which regulated organisations provide assurance about the quality of commercial software and infrastructure. The guidance acknowledges that direct audit of large software vendors (Microsoft, SAP, Salesforce) is generally not practical and describes alternative approaches: review of SOC 2 reports, ISO 27001 certification, vendor questionnaires and user group intelligence. The key principle is that the regulated organisation retains accountability for the GMP use of the system regardless of the supplier assurance approach used.
Implications for Existing Validation Programmes
Organisations do not need to immediately revalidate all existing systems to GAMP 5 Second Edition. The second edition is a guidance document, not a regulatory requirement, and regulatory expectations are set by the applicable regulations (EU GMP Annex 11, FDA 21 CFR Part 11) which have not changed.
However, organisations should consider the second edition's approach when:
- Onboarding new systems, new validation projects should follow the second edition approach
- Conducting periodic reviews, reviews can assess existing validation against second edition principles and identify gaps
- Assessing SaaS or cloud systems, where the second edition provides significantly more guidance than the first
- Responding to data integrity observations, where the second edition's integrated approach to data integrity may provide a more defensible remediation framework
Key Changes in GAMP 5 2nd Ed.
- Critical thinking emphasis
- Revised software categories
- Cloud & SaaS guidance
- Data integrity integration
- Stronger lifecycle approach
- Updated supplier assessment
- Modern architecture coverage
GAMP 5 and CSV Assessment
Sthira Assure conducts computer system validation assessments aligned to GAMP 5 Second Edition and EU GMP Annex 11.