Skip to main content
v2026.11,772 entries · CC-BY 4.0

GAMP 5 Second Edition: What Changed From the First Edition

GAMP 5 Second Edition (2022) replaced the 2008 first edition with the same risk-based CSV framework, but a genuinely different validation philosophy: critical, risk-based evaluation of evidential records instead of paper deliverables, new appendices for agile, AI/ML, blockchain and infrastructure, and explicit alignment with FDA’s Computer Software Assurance guidance.

Written and maintained by CASRAI Editorial Board

Last updated

GAMP 5 Second Edition was published by ISPE in July 2022, replacing the first edition that had stood since 2008. It keeps the same core framework the first edition established — a risk-based, lifecycle approach to computer system validation (CSV) scaled to a system’s GxP impact and software category — but it rewrites how that risk-based judgment gets exercised in practice, and it adds coverage for technology categories that barely existed when the first edition was written. If your organisation’s CSV procedures, templates or training still cite the 2008 edition, this page covers what actually changed and where your validation package is most likely to need updating.

For the mechanics of running a single validation exercise under GAMP 5 — software categories, the IQ/OQ/PQ sequence, 21 CFR Part 11 applicability — see Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11. This page deliberately doesn’t repeat that; it covers what the second edition changed relative to the first.

The core shift: from paper deliverables to critical thinking about evidence

The first edition’s practical legacy, whatever its intent, was often a documentation-heavy interpretation: validation as a stack of scripted test cases and signed paper deliverables, produced because the deliverable itself was treated as the evidence of compliance. The second edition explicitly reframes this. The stated shift is away from paper documentation as the validation “deliverable” and toward a critical, risk-based evaluation of the evidential records a system actually generates through its lifecycle — testing rigor and documentation depth should scale to the system’s real GxP risk, not default to maximal scripted testing for everything regardless of risk.

This is the same philosophy behind FDA’s Computer Software Assurance (CSA) initiative (see below), and the two efforts are explicitly aligned rather than coincidentally similar — GAMP 5 second edition was developed while CSA was in draft, and ISPE describes the two as complementary.

New appendices: agile, AI/ML, blockchain, and infrastructure

The first edition’s appendix structure (management appendices covering programme-level practices, development/operation appendices covering system-lifecycle practices) is preserved, but the second edition adds new appendices addressing technology and delivery models that the 2008 edition didn’t meaningfully cover:

  • Agile software development — a new development appendix acknowledging that GxP software is routinely built with agile and iterative methods now, not just waterfall. It states the GAMP lifecycle isn’t inherently linear and that validation activities can be integrated incrementally throughout an agile delivery cycle rather than bolted on at the end.
  • Software tools — a new appendix on the tools used to build and manage GxP software itself (e.g. requirements/test-management platforms), distinct from the regulated system under validation.
  • Distributed ledger systems (blockchain) — new coverage of validation considerations specific to blockchain-based systems, which the first edition had no framework for at all.
  • Artificial intelligence and machine learning (AI/ML) — new coverage addressing the validation challenge AI/ML systems pose: behavior that can evolve with retraining, in a framework built around systems whose behavior is otherwise fixed at release.
  • Infrastructure and critical thinking — new management appendices. The critical-thinking appendix is the closest thing to a practical playbook for the philosophy shift described above: how to actually justify a reduced-testing decision with a documented rationale, rather than defaulting to exhaustive scripted testing because it’s the safer paper trail.

None of this replaces the core software-category framework (the risk-tiered categories that drive how much validation rigor a given system needs) — that structure carries over. The new appendices extend it to cases the 2008 edition’s authors weren’t writing for.

Revised: electronic batch records and the operation phase

Beyond the new appendices, the sections covering electronic batch records (EBR) and the operational/maintenance phase of a validated system’s lifecycle were substantially rewritten, reflecting how much more common EBR and other electronic-record-generating systems had become in the 14 years since the first edition. Some first-edition topics were also combined or retired as part of the same rewrite, in favor of the consolidated critical-thinking framing above.

How this lines up with FDA’s Computer Software Assurance (CSA)

FDA’s CSA guidance, Computer Software Assurance for Production and Quality System Software, was circulated in draft the same year as GAMP 5 second edition (2022) and finalized on 24 September 2025. It’s scoped to production and quality system software under the Quality System Regulation (21 CFR Part 820) — a medical-device-manufacturing context, not a general Part 11 replacement — but its underlying approach (risk-based assurance activities, unscripted testing and critical thinking favored over exhaustive scripted testing for low-risk functionality) is the same philosophy GAMP 5 second edition formalizes more broadly. A lab or manufacturer already working under GAMP 5 second edition’s critical-thinking appendix is, in practice, already aligned with the direction CSA takes for the systems that fall inside its QSR scope.

What a validation package written against the first edition needs to gain

If your SOPs, validation master plan or templates were last updated against the 2008 edition, the realistic gap list is:

  • A documented critical-thinking rationale option for lower-risk systems or features — not a wholesale rewrite of every protocol, but a defined, auditable path for justifying reduced testing scope that doesn’t currently exist if your SOPs assume scripted testing by default.
  • Explicit handling for agile-delivered systems, if any regulated system in your inventory is built or configured through iterative sprints rather than a single waterfall release — the validation activities need a defined touchpoint inside that cadence, not a single end-of-project validation event.
  • A stated position on AI/ML-based systems, if any are in scope or on the roadmap — even a short SOP section acknowledging that a system whose behavior changes with retraining needs a different validation-maintenance approach than a static system is a meaningful gap-closer.
  • An updated system inventory categorisation pass confirming which systems now fall under the newer appendices (agile-delivered, AI/ML-based, blockchain-based) so periodic review captures them correctly. See Validation Master Plan (VMP) for a Regulated Laboratory for how that inventory and its periodic-review cycle should be structured.

None of this requires re-validating systems that were correctly validated under the first edition’s framework — the core lifecycle and category structure didn’t change. The gap is in SOP and template coverage for what the second edition added, not in the validity of prior work.

Frequently asked questions

Do I need to re-validate existing systems because GAMP 5 moved to a second edition?

No. The second edition didn’t invalidate work done correctly under the first edition’s framework — the risk-based lifecycle and software-category structure are unchanged. Update your SOPs and templates to cover the new appendices going forward; there’s no retroactive requirement to redo prior validation.

Is GAMP 5 second edition a regulatory requirement?

No. GAMP 5 (either edition) is an ISPE industry guidance document, not a regulation. It’s a widely accepted framework for meeting the actual regulatory requirements — principally 21 CFR Part 11 and EU GMP Annex 11 for computerised systems — but an inspector cites the regulation, not the GAMP guide, even though GAMP 5-aligned practice is the de facto industry standard they’ll expect to see.

Does GAMP 5 second edition replace FDA’s Computer Software Assurance guidance, or vice versa?

Neither replaces the other. CSA is FDA guidance scoped specifically to production and quality system software under 21 CFR Part 820 (medical device manufacturing). GAMP 5 second edition is broader, industry-wide guidance covering GxP computer systems generally. They share the same risk-based, critical-thinking philosophy and are explicitly aligned, but a lab or manufacturer outside CSA’s QSR scope still looks to GAMP 5, not CSA, as its framework.

Where can I get the actual GAMP 5 second edition text?

Directly from ISPE, who publish and sell it — it isn’t a freely published regulatory document. See ISPE’s own guidance-document page for current access and pricing.

Related CASRAI resources

Primary sources

  • ISPE, GAMP 5 Guide, 2nd Edition — ispe.org/publications/guidance-documents/gamp-5-guide-2nd-edition (publisher’s own listing; the guide itself is a paid ISPE publication, not freely republished)
  • FDA, Computer Software Assurance for Production and Quality System Software — final guidance, Federal Register, 24 September 2025
  • ECA Academy, industry review and summary of GAMP 5 second edition’s structural and philosophical changes — gmp-compliance.org/gmp-news/review-of-gamp5-second-edition

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · included with Regulatory Radar

Ask about GAMP 5 Second Edition: What Changed From the First Edition

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.