Direct comparison
GAMP 4 vs. GAMP 5: What Changed
GAMP 4 (2001) vs. GAMP 5 (2008): the V-model to risk-based shift, five categories to four, and whether legacy GAMP 4 validation needs redoing.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · included with Regulatory Radar
Ask about GAMP 4 vs. GAMP 5: What Changed
Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.
150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do GAMP 4 (2001), GAMP 5 (2008) compare side by side?
The table below compares GAMP 4 (2001), GAMP 5 (2008) across 8 procurement-relevant dimensions, from full title & publication through do prior validations need redoing?.
Side-by-side comparison
| Dimension | GAMP 4 (2001) | GAMP 5 (2008) |
|---|---|---|
| Full title & publication | Guide for Validation of Automated Systems, published December 2001 | A Risk-Based Approach to Compliant GxP Computerized Systems, published February 2008 (second edition, July 2022) |
| Core organising principle | A largely prescriptive, document-centric V-model applied fairly uniformly across systems | Risk management as the central organising principle -- validation depth scales to the system's assessed GxP risk |
| Software categories | Five categories: 1 (operating systems), 2 (firmware), 3 (standard packages), 4 (configurable packages), 5 (custom software) | Four active categories: 1, 3, 4, 5 -- Category 2 (firmware) removed; firmware now classified under whichever remaining category fits |
| Supplier / vendor documentation | Practice tended toward re-verifying and re-documenting vendor testing independently | Explicitly encourages leveraging supplier assessment and documentation where adequate, scaled to category and risk, instead of duplicating it |
| Life-cycle deliverables | Fixed V-model deliverable sequence (URS, functional spec, design spec, mirrored by OQ/PQ testing), applied largely the same regardless of risk | Life-cycle activities and deliverable depth scale with the system's category and risk assessment -- a small configured system doesn't get the same package as a large custom one |
| Risk management maturity | Introduced the concept of system risk as one consideration among several | Risk assessment drives the whole framework, not just one input to it |
| Current status | Not maintained or reissued since 2001; not cited as current guidance by regulators or industry | Current, actively maintained framework; now in its second edition (2022) -- no GAMP 6 exists |
| Do prior validations need redoing? | N/A -- this is the legacy framework in question | No. Systems correctly validated under GAMP 4 don't need re-validation solely because GAMP 5 superseded it; only SOPs/templates and new work need to move to the current framework |
Common questions
Common questions about GAMP 4 (2001) vs GAMP 5 (2008)
Do I need to re-validate systems that were validated under GAMP 4?
+
No. A system correctly validated under GAMP 4's framework at the time it was validated doesn't need to be redone solely because GAMP 5 superseded it. The practical work is updating SOPs, templates and any new validation activity to the current framework going forward, not retroactively reworking prior, correctly-executed validation.
What happened to GAMP 4's Category 2 (firmware)?
+
It was removed. GAMP 5 uses four active categories (1, 3, 4, 5); firmware is now classified under whichever of those actually fits the specific system -- typically Category 1 as embedded infrastructure, or Category 3, 4 or 5 depending on how configurable it is.
Is GAMP 4 or GAMP 5 a regulatory requirement?
+
Neither. Both are ISPE industry guidance documents, not regulations. GAMP 5 is the de facto industry standard for meeting the actual regulatory requirements -- principally 21 CFR Part 11 and EU GMP Annex 11 for computerised systems -- and is what an inspector will expect current practice to reflect, even though the citable regulation is Part 11 or Annex 11, not GAMP itself.
Is there a GAMP 6?
+
No. The current document is GAMP 5, second edition (2022). There has been no GAMP 6 as of this writing.
Going deeper








