International (pharmaceutical, biotechnology and medical device industry guidance)

GAMP 5

147 controls. 90 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

147 controls 90 frameworks share controls with it International (pharmaceutical, biotechnology and medical device industry guidance) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
GAMP5-2nd-Edition-AI-Cloud-Agile-CSA2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)27
GAMP5-CrossMapping-NIST-ISOCrosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL0
GAMP5-Crosswalk-ICH-FDA-EMA-MHRACrosswalk to ICH Q9/Q10, FDA Part 11, EU Annex 11, MHRA Data Integrity and Sectoral Standards0
GAMP5-DataIntegrity-Part11-Annex11Data Integrity (ALCOA+), 21 CFR Part 11 + EU Annex 11 + Electronic Records0
GAMP5-ISPE-Status-Copyright-CoordinationISPE Guide Status, Copyright, GxP Regulatory Coordination and 2024-2025 Updates0
GAMP5-Implementation-RoadmapGAMP 5 Implementation Roadmap - Organizational Roles, Training and Tooling0
GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQV-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability68
GAMP5-Risk-CriticalThinkingRisk-Based Approach, Critical Thinking and 5 Key Concepts69
GAMP5-Software-Categories5 Software Categories (Appendix M4) - Infrastructure, Non-Configured, Configured, Custom1
GAMP5-Status-2024-2025-CSA-AIGAMP 5 Status, FDA CSA Final Guidance and AI/ML in Pharma 2024-20250
GAMP5-Supplier-Operations-Change-PeriodicSupplier Assessment, Operational Phase, Change Control and Periodic Review28
1Chapter 1 Introduction: rationale, new material, purpose, scope, benefits and structure0
2Chapter 2 Key Concepts0
2.1.12.1.1 Product and Process Understanding0
2.1.22.1.2 Life Cycle Approach within a Quality Management System0
2.1.32.1.3 Scalable Life Cycle Activities0
2.1.42.1.4 Science-Based Quality Risk Management0
2.1.52.1.5 Leveraging Supplier Involvement0
2.22.2 Key Terms0
3Chapter 3 Life Cycle Approach0
3.13.1 Computerized System Life Cycle0
3.23.2 Specification and Verification0
3.33.3 Computerized System Validation Framework0
3.43.4 Critical Thinking Through the Life Cycle0
4Chapter 4 Life Cycle Phases0
4.14.1 Concept Phase0
4.24.2 Project Phase0
4.2.14.2.1 Project Planning0
4.2.24.2.2 Specification, Configuration and Coding0
4.2.34.2.3 Verification0
4.2.44.2.4 Reporting and Release0
4.2.54.2.5 Supporting Processes0
4.2.5.14.2.5.1 Risk Management as a Supporting Process0
4.2.5.24.2.5.2 Project Change and Configuration Management0
4.2.5.34.2.5.3 Design Review0
4.2.5.44.2.5.4 Traceability0
4.2.5.54.2.5.5 Documentation Management and Knowledge Management0
4.2.64.2.6 Specification and Verification by Software Category0
4.34.3 Operation Phase0
4.3.14.3.1 Operation: Handover0
4.3.24.3.2 Operation: Service Management and Performance Monitoring0
4.3.34.3.3 Operation: Incident and Problem Management and CAPA0
4.3.44.3.4 Operation: Change and Configuration Management0
4.3.54.3.5 Operation: Periodic Review0
4.3.64.3.6 Operation: Continuity Management0
4.3.74.3.7 Operation: Security and System Administration0
4.3.84.3.8 Operation: Record Management0
4.44.4 Retirement Phase: Withdrawal, Decommissioning and Disposal0
5Chapter 5 Quality Risk Management0
5.15.1 Overview of Quality Risk Management0
5.25.2 Science-Based Quality Risk Management0
5.35.3 Quality Risk Management Process0
6Chapter 6 Regulated Company Activities0
6.16.1 Governance for Achieving Compliance0
6.1.16.1.1 Computerized Systems Policies and Procedures0
6.1.26.1.2 Identifying Clear Roles and Responsibilities0
6.1.36.1.3 Training0
6.1.46.1.4 Managing Supplier Relationships0
6.1.56.1.5 Maintaining the System Inventory0
6.1.66.1.6 Planning for Validation0
6.1.76.1.7 Continual Improvement Activities0
6.1.86.1.8 Data Governance0
6.26.2 System-Specific Activities0
6.2.16.2.1 Identify Compliance Standards0
6.2.106.2.10 Reporting and Release0
6.2.116.2.11 Maintaining System Compliance During Operation0
6.2.126.2.12 System Retirement0
6.2.26.2.2 Identify System0
6.2.36.2.3 Identify Key Individuals0
6.2.46.2.4 Requirements Specification0
6.2.56.2.5 Determine Strategy for Achieving Compliance and Fitness for Intended Use0
6.2.66.2.6 Planning0
6.2.76.2.7 System Specifications and Design Reviews0
6.2.86.2.8 Development and Review of Software for Custom Applications0
6.2.96.2.9 Test Strategy and Testing0
7Chapter 7 Supplier Activities0
7.17.1 Supplier Products, Applications and Services0
7.107.10 Supplier Testing0
7.117.11 Commercial Release0
7.127.12 User Documentation and Training0
7.137.13 System Support and Maintenance During Operation0
7.147.14 System Replacement and Retirement0
7.27.2 Supplier Good Practices0
7.37.3 Supplier Quality Management System0
7.47.4 Supplier Requirements0
7.57.5 Supplier Quality Planning and Prototyping0
7.67.6 Sub-Supplier Assessments0
7.77.7 Supplier Specifications0
7.87.8 Supplier Design Reviews0
7.97.9 Software Production and Configuration0
8Chapter 8 Efficiency Improvements0
8.18.1 Establishing Verifiable and Objective User Requirements0
8.28.2 Making Risk-Based Decisions0
8.38.3 Leveraging Supplier Input0
8.48.4 Leveraging Existing Information0
8.58.5 Using Efficient Testing Practices0
8.68.6 Employing a Well-Managed Handover Process0
8.78.7 Managing Changes Efficiently0
8.88.8 Anticipating Data Archiving and Migration Needs0
8.98.9 Using Tools and Automation0
DDevelopment Appendices (D1 to D11)0
D1Appendix D1 Specifying Requirements0
D10Appendix D10 Distributed Ledger Systems0
D11Appendix D11 Artificial Intelligence and Machine Learning0
D2Appendix D2 (Retired) Functional Specifications0
D3Appendix D3 Configuration and Design0
D4Appendix D4 Management, Development and Review of Software0
D5Appendix D5 Testing of Computerized Systems0
D6Appendix D6 System Descriptions0
D7Appendix D7 Data Migration0
D8Appendix D8 Agile Software Development0
D9Appendix D9 Software Tools0
GAppendices G1 References and G2 Glossary0
MManagement Appendices (M1 to M12)0
M1Appendix M1 Validation Planning0
M10Appendix M10 System Retirement0
M11Appendix M11 IT Infrastructure0
M12Appendix M12 Critical Thinking0
M2Appendix M2 Supplier Assessment0
M3Appendix M3 Science-Based Quality Risk Management0
M4Appendix M4 Categories of Software and Hardware0
M5Appendix M5 Design Review and Traceability0
M6Appendix M6 Supplier Quality Planning0
M7Appendix M7 Validation Reporting0
M8Appendix M8 Project Change and Configuration Management0
M9Appendix M9 Documentation and Information Management0
OOperation Appendices (O1 to O13)0
O1Appendix O1 Handover0
O10Appendix O10 Business Continuity Management0
O11Appendix O11 Security Management0
O12Appendix O12 System Administration0
O13Appendix O13 Archiving and Retrieval0
O2Appendix O2 Establishing and Managing Support Services0
O3Appendix O3 System Monitoring0
O4Appendix O4 Incident Management and Problem Management0
O5Appendix O5 Corrective and Preventive Action0
O6Appendix O6 Operational Change and Configuration Management0
O7Appendix O7 (Retired) Repair Activity0
O8Appendix O8 Periodic Review0
O9Appendix O9 Backup and Restore0
SSpecial Interest Appendices (S1 to S6)0
S1Appendix S1 Alignment with ASTM E25000
S2Appendix S2 Electronic Production Records0
S3Appendix S3 End User Applications Including Spreadsheets0
S4Appendix S4 Patch and Update Management0
S5Appendix S5 (Retired) Managing Quality within an Outsourced IS/IT Environment0
S6Appendix S6 Organizational Change0

Tell me when GAMP 5 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Role inventory + RACI
  • Metrics + management review
  • Annual cycle documentation
  • Supervisory dialogue records
  • Role inventory + RACI + DPO designation
  • Operational controls + tooling investment
  • Reporting process + content index
  • Examination response procedures
  • Tooling + metrics dashboard
  • GAMP 5 2nd Edition licensed copy + adoption

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for GAMP 5, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition