Written and maintained by CASRAI Editorial Board
Last updated
GAMP 5 Second Edition was published by ISPE in July 2022, replacing the first edition that had stood since 2008. It keeps the same core framework the first edition established — a risk-based, lifecycle approach to computer system validation (CSV) scaled to a system’s GxP impact and software category — but it rewrites how that risk-based judgment gets exercised in practice, and it adds coverage for technology categories that barely existed when the first edition was written. If your organisation’s CSV procedures, templates or training still cite the 2008 edition, this page covers what actually changed and where your validation package is most likely to need updating.
For the mechanics of running a single validation exercise under GAMP 5 — software categories, the IQ/OQ/PQ sequence, 21 CFR Part 11 applicability — see Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11. This page deliberately doesn’t repeat that; it covers what the second edition changed relative to the first.
The core shift: from paper deliverables to critical thinking about evidence
The first edition’s practical legacy, whatever its intent, was often a documentation-heavy interpretation: validation as a stack of scripted test cases and signed paper deliverables, produced because the deliverable itself was treated as the evidence of compliance. The second edition explicitly reframes this. The stated shift is away from paper documentation as the validation “deliverable” and toward a critical, risk-based evaluation of the evidential records a system actually generates through its lifecycle — testing rigor and documentation depth should scale to the system’s real GxP risk, not default to maximal scripted testing for everything regardless of risk.
This is the same philosophy behind FDA’s Computer Software Assurance (CSA) initiative (see below), and the two efforts are explicitly aligned rather than coincidentally similar — GAMP 5 second edition was developed while CSA was in draft, and ISPE describes the two as complementary.
New appendices: agile, AI/ML, blockchain, and infrastructure
The first edition’s appendix structure (management appendices covering programme-level practices, development/operation appendices covering system-lifecycle practices) is preserved, but the second edition adds new appendices addressing technology and delivery models that the 2008 edition didn’t meaningfully cover:
- Agile software development — a new development appendix acknowledging that GxP software is routinely built with agile and iterative methods now, not just waterfall. It states the GAMP lifecycle isn’t inherently linear and that validation activities can be integrated incrementally throughout an agile delivery cycle rather than bolted on at the end.
- Software tools — a new appendix on the tools used to build and manage GxP software itself (e.g. requirements/test-management platforms), distinct from the regulated system under validation.
- Distributed ledger systems (blockchain) — new coverage of validation considerations specific to blockchain-based systems, which the first edition had no framework for at all.
- Artificial intelligence and machine learning (AI/ML) — new coverage addressing the validation challenge AI/ML systems pose: behavior that can evolve with retraining, in a framework built around systems whose behavior is otherwise fixed at release.
- Infrastructure and critical thinking — new management appendices. The critical-thinking appendix is the closest thing to a practical playbook for the philosophy shift described above: how to actually justify a reduced-testing decision with a documented rationale, rather than defaulting to exhaustive scripted testing because it’s the safer paper trail.
None of this replaces the core software-category framework (the risk-tiered categories that drive how much validation rigor a given system needs) — that structure carries over. The new appendices extend it to cases the 2008 edition’s authors weren’t writing for.
Revised: electronic batch records and the operation phase
Beyond the new appendices, the sections covering electronic batch records (EBR) and the operational/maintenance phase of a validated system’s lifecycle were substantially rewritten, reflecting how much more common EBR and other electronic-record-generating systems had become in the 14 years since the first edition. Some first-edition topics were also combined or retired as part of the same rewrite, in favor of the consolidated critical-thinking framing above.
How this lines up with FDA’s Computer Software Assurance (CSA)
FDA’s CSA guidance, Computer Software Assurance for Production and Quality System Software, was circulated in draft the same year as GAMP 5 second edition (2022) and finalized on 24 September 2025. It’s scoped to production and quality system software under the Quality System Regulation (21 CFR Part 820) — a medical-device-manufacturing context, not a general Part 11 replacement — but its underlying approach (risk-based assurance activities, unscripted testing and critical thinking favored over exhaustive scripted testing for low-risk functionality) is the same philosophy GAMP 5 second edition formalizes more broadly. A lab or manufacturer already working under GAMP 5 second edition’s critical-thinking appendix is, in practice, already aligned with the direction CSA takes for the systems that fall inside its QSR scope.
What a validation package written against the first edition needs to gain
If your SOPs, validation master plan or templates were last updated against the 2008 edition, the realistic gap list is:
- A documented critical-thinking rationale option for lower-risk systems or features — not a wholesale rewrite of every protocol, but a defined, auditable path for justifying reduced testing scope that doesn’t currently exist if your SOPs assume scripted testing by default.
- Explicit handling for agile-delivered systems, if any regulated system in your inventory is built or configured through iterative sprints rather than a single waterfall release — the validation activities need a defined touchpoint inside that cadence, not a single end-of-project validation event.
- A stated position on AI/ML-based systems, if any are in scope or on the roadmap — even a short SOP section acknowledging that a system whose behavior changes with retraining needs a different validation-maintenance approach than a static system is a meaningful gap-closer.
- An updated system inventory categorisation pass confirming which systems now fall under the newer appendices (agile-delivered, AI/ML-based, blockchain-based) so periodic review captures them correctly. See Validation Master Plan (VMP) for a Regulated Laboratory for how that inventory and its periodic-review cycle should be structured.
None of this requires re-validating systems that were correctly validated under the first edition’s framework — the core lifecycle and category structure didn’t change. The gap is in SOP and template coverage for what the second edition added, not in the validity of prior work.
Frequently asked questions
Do I need to re-validate existing systems because GAMP 5 moved to a second edition?
No. The second edition didn’t invalidate work done correctly under the first edition’s framework — the risk-based lifecycle and software-category structure are unchanged. Update your SOPs and templates to cover the new appendices going forward; there’s no retroactive requirement to redo prior validation.
Is GAMP 5 second edition a regulatory requirement?
No. GAMP 5 (either edition) is an ISPE industry guidance document, not a regulation. It’s a widely accepted framework for meeting the actual regulatory requirements — principally 21 CFR Part 11 and EU GMP Annex 11 for computerised systems — but an inspector cites the regulation, not the GAMP guide, even though GAMP 5-aligned practice is the de facto industry standard they’ll expect to see.
Does GAMP 5 second edition replace FDA’s Computer Software Assurance guidance, or vice versa?
Neither replaces the other. CSA is FDA guidance scoped specifically to production and quality system software under 21 CFR Part 820 (medical device manufacturing). GAMP 5 second edition is broader, industry-wide guidance covering GxP computer systems generally. They share the same risk-based, critical-thinking philosophy and are explicitly aligned, but a lab or manufacturer outside CSA’s QSR scope still looks to GAMP 5, not CSA, as its framework.
Where can I get the actual GAMP 5 second edition text?
Directly from ISPE, who publish and sell it — it isn’t a freely published regulatory document. See ISPE’s own guidance-document page for current access and pricing.
Related CASRAI resources
- Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11
- Validation Master Plan (VMP) for a Regulated Laboratory
- Computerised System Validation Under EU GMP: Annex 15 and Annex 11
- Computer Software Assurance (CSA) vs. Computer System Validation (CSV)
- User Requirements Specification (URS)
- IQ/OQ/PQ (Installation, Operational, and Performance Qualification)
- 21 CFR Part 11: Electronic Records & Signatures
- ALCOA+ (Clinical Trial Data Integrity Principles)
Primary sources
- ISPE, GAMP 5 Guide, 2nd Edition — ispe.org/publications/guidance-documents/gamp-5-guide-2nd-edition (publisher’s own listing; the guide itself is a paid ISPE publication, not freely republished)
- FDA, Computer Software Assurance for Production and Quality System Software — final guidance, Federal Register, 24 September 2025
- ECA Academy, industry review and summary of GAMP 5 second edition’s structural and philosophical changes — gmp-compliance.org/gmp-news/review-of-gamp5-second-edition








