GAMP 5 is the ISPE guide “A Risk-Based Approach to Compliant GxP Computerized Systems” for the proper handling of GxP computerized systems. It describes a patient-centric, risk-based lifecycle approach designed to protect patient safety, product quality, and data integrity. The second edition is intended as a practical guide and not as an immediately binding regulation.
Guiding Principle: Appropriate, Not Schematic
GAMP 5 aligns the effort for specification, vendor management, testing, and operational measures with the significance of the respective system function. A tool that performs randomized allocation or processes critical safety data requires a different depth of evidence than an application without GxP-relevant decisions. The guide is specifically not intended to prescribe a rigid, one-size-fits-all method, but rather to enable justified, proportionate practices.
The approach begins with the system’s intended purpose. Requirements, risks, and controls are not collected in isolation for software functions, but are assessed based on the potential impact of an error on patients, product quality, or the reliability of regulated data. Business process experts must therefore be involved in decisions; technical test evidence alone does not explain what use is considered acceptable.
Lifecycle and Service Providers
GAMP promotes a holistic view across conception, procurement or development, configuration, release, operation, modification, and decommissioning. Different types of evidence are generated at each stage: user requirements specify the purpose, tests demonstrate the implementation of critical functions, and operational processes manage access, incidents, data backup, or changes. The validation status is thus a continuously maintained outcome.
According to ISPE, the second edition also considers service providers and iterative development. This is relevant for cloud-based EDC or eTMF solutions, as vendor performance, configuration, and accountability must be interconnected. A vendor can provide documentation and test materials, but the decision of whether the provided solution covers the company’s own regulated use case remains with the user.
Distinction from Computerized System Validation
GAMP 5 is the guide whose principles can be used to design a risk-based validation approach. Computerized System Validation, on the other hand, is the concrete, documented activity and proof that a specific system remains suitable for its intended use. The guide does not replace user requirements, test protocols, or release decisions for an individual system.
GxP is also broader. It refers to the regulated quality environment in which requirements from good clinical, manufacturing, laboratory, or distribution practices may apply. GAMP 5 focuses on computerized systems within such environments. It does not follow that every technical application automatically receives the same validation scope according to GAMP 5.
For application, “risk-based” also means that existing vendor evidence can be used purposefully. However, its adoption occurs after an evaluation of its relevance for one’s own configuration, not as a blanket exemption. For example, a vendor can provide standard tests for core functionality, while the study-specific integration of an ePRO system into the EDC requires additional tests by the sponsor or their service provider. The evidence strategy should link critical functions with the appropriate documentation.
GAMP 5 emphasizes traceable professional judgment. A test plan that provides the same depth of testing for all applications can tie up resources on less critical details while under-weighting an essential interface. Conversely, an agile development approach must not lead to unclear requirements, changes, and releases. The guide offers conceptual models and tools for this, but does not determine specific internal organizational work instructions.
This ensures resources remain concentrated where a system error could genuinely impair clinical decision-making, participant protection, or the integrity of a submission dataset.
The justification for the weighting must be comprehensibly documented for the respective system function.
Relevance for clinical trials
In clinical trials, GAMP 5 helps shift the discussion about EDC, eTMF, ePRO, or randomization from the question “Is the system validated?” to the specific risks of use. Particularly crucial are the protocol-relevant configuration, the evidence for interfaces, authorizations, and version changes, as well as the handling of deviations. A generic vendor report does not replace an assessment of the study-specific setup.
Full-service CROs like Mediconomics support with risk-based user requirements, vendor assessments, and validation plans for study-related systems. They can coordinate test cases for critical data flows, evaluate change control documentation, and link the release of EDC, ePRO, or IRT configurations with data management, clinical operations, and quality management.
Frequently Asked Questions (FAQ)
Is GAMP 5 itself a legal requirement?
No. ISPE describes GAMP as a guide and explicitly not as a standard or prescribed method. It helps in interpreting regulated expectations for GxP systems.
Does GAMP 5 only apply to software developed in-house?
No. The approach is also relevant for configured standard software and services provided by vendors, as their suitability for intended use must be evaluated.
Does the work end after system release?
No. The lifecycle approach also includes operation, changes, and controlled decommissioning. New risks may require re-evaluation or additional evidence.
Regulatory References
- ISPE GAMP 5 Guide, Second Edition – describes the risk-based lifecycle approach for GxP systems.
- EudraLex Volume 4, Annex 11 – requires risk-based validation and data integrity controls.
- EMA/INS/GCP/112288/2023 – transfers expectations for computerized systems to clinical trials.