EMS

What’s New in GAMP 5? What Regulated Organizations Need to Know

Author: Gagan Kaur

Aug 19, 2026

GAMP 5

Computerized systems have become essential to pharmaceutical, biotechnology, medical device, healthcare, and other regulated operations. They collect critical data, automate processes, issue alarms, maintain electronic records, and support decisions that can affect product quality and patient safety.  As these systems become more connected and increasingly rely on cloud services, automation, and artificial intelligence, the methods used to validate them must also evolve.

The International Society for Pharmaceutical Engineering addressed this changing environment with the second edition of GAMP 5. Although published in 2022, GAMP 5 Second Edition remains the latest version of the core guide as of 2026. More recent guidance from ISPE, FDA, and European regulators continues to reinforce its risk-based approach.

Here is what regulated organizations should understand about these developments and how they apply to computerized environmental monitoring systems.

What Is GAMP 5?

GAMP stands for Good Automated Manufacturing Practice. Developed by ISPE, GAMP 5 provides a framework for establishing and maintaining computerized systems that are fit for their intended use in GxP-regulated environments.

GAMP 5 is not a regulation, and systems do not receive a “GAMP certification.” Instead, the guide helps regulated organizations interpret regulatory expectations and develop an appropriate approach to computerized system validation.

Its fundamental objective is to protect:

  • Patient safety
  • Product quality
  • Data integrity

GAMP accomplishes this by applying quality risk management throughout the computerized system lifecycle, from initial requirements and supplier selection through implementation, operation, change control, and retirement.

What Changed in GAMP 5 Second Edition?

The second edition retained the lifecycle and risk-based foundation of the original GAMP 5 guide. The most significant changes relate to how organizations apply those principles to modern technology.

Greater Emphasis on Critical Thinking

One of the most important developments is the stronger emphasis on critical thinking.

Traditional validation programs sometimes apply the same documentation and testing requirements to every system function, regardless of its potential impact. This can result in extensive testing that does not necessarily improve product quality or reduce meaningful risk.

GAMP 5 Second Edition encourages subject matter experts to evaluate what could go wrong, how serious the consequences could be, and which controls provide the greatest assurance.

This does not mean eliminating documentation or testing. It means directing the greatest attention toward functions that could affect patient safety, product quality, or data integrity.

For an environmental monitoring system, higher-risk functions may include:

  • Environmental data collection
  • Alarm generation and notification
  • Alarm-limit configuration
  • User access and permissions
  • Audit trails
  • Electronic records
  • Report generation
  • Backup and data recovery

Lower-risk administrative features may not require the same level of formal testing. The reasoning behind the chosen approach should still be documented.

Movement Toward Computer Software Assurance

GAMP 5 Second Edition also reflects the industry’s movement from traditional Computer System Validation, or CSV, toward Computer Software Assurance, commonly called CSA.

CSA is a risk-based approach for establishing confidence that software is fit for its intended use. It encourages organizations to select the most appropriate assurance activities based on the risk and complexity of each function.

Depending on the risk, acceptable testing methods may include:

  • Formal scripted testing
  • Unscripted or exploratory testing
  • Scenario-based testing
  • Supplier testing
  • Automated testing
  • Performance monitoring

High-risk functions may still require detailed test scripts, expected results, supporting evidence, and formal approval. Lower-risk functions may be evaluated using less prescriptive methods.

In February 2026, FDA issued its final guidance on Computer Software Assurance for Production and Quality Management System Software. Its direct scope is software used in medical device production and quality management systems, but the guidance reinforces the broader industry shift toward risk-based assurance.

More Reliance on Supplier Knowledge

Modern regulated systems frequently contain commercial software, configured applications, cloud services, and third-party infrastructure. Customers may not have direct visibility into every component or line of code.

GAMP 5 Second Edition places greater importance on supplier assessment and the appropriate use of supplier documentation.

A regulated company may be able to use evidence provided by a qualified supplier, including:

  • Product specifications
  • Development and testing documentation
  • Quality certifications
  • Release notes
  • Security information
  • Installation records
  • Configuration documentation
  • Supplier audit results
  • Technical support procedures

Leveraging credible supplier evidence can reduce unnecessary duplicate testing. However, the regulated company remains responsible for defining its intended use, assessing risk, approving the system, and confirming that the configured application supports its regulated processes.

Recognition of Cloud and SaaS Environments

Cloud-hosted and Software-as-a-Service applications are now common across regulated industries. GAMP 5 Second Edition recognizes that these systems require a shared-responsibility model.

Customers should clearly understand which responsibilities belong to the software supplier, cloud provider, internal IT department, and system owner.

Areas requiring particular attention include:

  • Data ownership
  • System availability
  • Cybersecurity
  • User and administrator access
  • Backup and restoration
  • Disaster recovery
  • Data retention
  • Data location
  • Software updates
  • Incident management
  • Business continuity
  • System retirement and data export

The use of a cloud service does not transfer regulatory accountability to the provider. Responsibilities should be documented through agreements, procedures, and system lifecycle records.

Support for Agile Development

Earlier validation programs were often structured around a linear development model in which requirements, design, testing, and release occurred in separate phases.

GAMP 5 Second Edition explicitly recognizes agile and iterative development practices. Requirements, risk assessments, testing, and approvals may be completed incrementally as software is developed and updated.

Organizations must still maintain appropriate controls, traceability, testing evidence, and approval. Agile development changes how those activities are organized, not whether they are required.

This is especially important for cloud systems that receive more frequent software releases than traditional on-premises applications.

Increased Attention to Emerging Technologies

The second edition expanded its consideration of technologies such as:

  • Artificial intelligence and machine learning
  • Blockchain and distributed ledgers
  • Open-source software
  • Automation tools
  • Modern cloud infrastructure

ISPE has since released a dedicated GAMP guide addressing artificial intelligence. This guidance examines factors such as intended use, data quality, model performance, human oversight, explainability, retraining, change control, and model drift.

For environmental monitoring, AI could eventually support functions such as anomaly detection, predictive maintenance, and alarm analysis. If AI influences a GxP decision, organizations will need controls appropriate to the risk and behavior of the model.

What Has Not Changed?

Despite the increased flexibility, the essential responsibilities surrounding computerized systems remain.

Regulated organizations must still:

  • Define the system’s intended use
  • Establish clear and testable requirements
  • Assess GxP and data-integrity risks
  • Evaluate the supplier
  • Confirm that the system is properly installed and configured
  • Test critical functions
  • Maintain traceable validation evidence
  • Control access and system changes
  • Investigate incidents
  • Periodically review the system
  • Maintain the system in a validated state
  • Retain and retrieve regulated records

GAMP’s familiar software categories also remain available. However, a software category should not be used by itself to determine the complete validation strategy. Intended use, configuration, complexity, supplier maturity, and risk should all be considered.

How the Proposed EU Annex 11 Revision Fits In

The European Commission has also proposed a major revision to EU GMP Annex 11, which addresses computerized systems.

The proposed revision would strengthen expectations concerning:

  • Computerized system lifecycle management
  • Quality risk management
  • Supplier and service-provider oversight
  • Alarm management
  • Audit-trail review
  • Identity and access management
  • Electronic signatures
  • Cybersecurity
  • Backup and restoration
  • Data archiving
  • Periodic review
  • Data integrity and governance

As of August 2026, the revised Annex 11 remains a draft, and the current 2011 version is still listed in EudraLex. Organizations should not treat the proposed requirements as final. However, the draft provides useful insight into the direction of European regulatory expectations.

Many of its proposed principles are already consistent with GAMP 5 Second Edition.

What Does This Mean for Environmental Monitoring Systems?

A computerized environmental monitoring system may create and retain records used to demonstrate that regulated materials, products, equipment, or facilities remained within established conditions.

A risk-based validation approach should therefore give particular attention to the complete data path, from the sensor taking a reading to the record appearing in the software.

Organizations should consider questions such as:

  • Are readings collected accurately and at the required frequency?
  • What happens if communication is interrupted?
  • Are alarms generated at the correct limits?
  • Are notifications delivered to the appropriate personnel?
  • Can alarm settings be changed only by authorized users?
  • Are configuration changes captured in the audit trail?
  • Are records protected from unauthorized alteration or deletion?
  • Can data be retrieved throughout the required retention period?
  • Are backup and restoration procedures tested?
  • Are software updates assessed before deployment?
  • Are calibration and validation activities properly documented?

The answers should be supported by requirements, risk assessments, configuration records, supplier documentation, and appropriate testing.

Applying GAMP Principles With Rees Scientific

Rees Scientific supports customers throughout the lifecycle of the Rees Monitoring System, from system design and installation through validation, calibration, training, service, and ongoing support.

Depending on the project scope, supporting documentation and services may include system specifications, installation records, configuration information, qualification protocols, executed testing, calibration documentation, training, and change-related information.

This documentation can help customers apply a GAMP-based validation strategy and demonstrate that their configured monitoring system is fit for its intended use.

The customer ultimately owns the validation decision because each organization must define how the system will be used within its regulated processes. A strong partnership between the customer and system supplier makes it easier to establish clear responsibilities, focus testing on meaningful risks, and maintain the system in a validated state.

A More Focused Approach to Assurance

The latest GAMP developments do not remove the need for validation. They encourage organizations to make validation more thoughtful, focused, and relevant.

The central question is no longer, “How much documentation can we produce?” It is, “What evidence do we need to demonstrate that this system performs reliably and protects our critical processes and data?”

For environmental monitoring systems, that means understanding intended use, concentrating on high-risk functions, making appropriate use of supplier evidence, and maintaining control throughout the system lifecycle.

Frequently Asked Questions About GAMP 5

1. What does GAMP stand for?

GAMP stands for Good Automated Manufacturing Practice. Developed by the International Society for Pharmaceutical Engineering, GAMP provides guidance for establishing and maintaining computerized systems that are fit for their intended use in regulated environments.

2. Is GAMP 5 a regulatory requirement?

GAMP 5 is not a regulation. It is an industry guidance framework that helps organizations apply regulatory expectations to computerized systems using a lifecycle-based, risk-based approach. Regulators may recognize GAMP as an accepted industry practice, but following it does not replace compliance with applicable regulations.

3. What is the latest version of GAMP?

GAMP 5 Second Edition, published in 2022, remains the latest version of the core guide as of August 2026. It places greater emphasis on critical thinking, supplier involvement, data integrity, cloud services, agile development, and Computer Software Assurance.

4. Can a computerized monitoring system be GAMP certified?

No. GAMP does not provide product certifications. A system should be evaluated and validated for its intended use within the customer’s specific regulated environment. Suppliers can provide documentation and services that support a GAMP-based validation approach, but the regulated organization remains responsible for approving its system.

5. How does GAMP 5 apply to the Rees Monitoring System?

GAMP 5 can help customers establish a risk-based validation strategy for the Rees Monitoring System. The process may include defining intended use, assessing system risks, evaluating critical functions, reviewing supplier documentation, executing qualification testing, and maintaining the system in a validated state. Rees Scientific can support this process with system documentation, qualification services, calibration, training, and ongoing technical support.

Need support validating your environmental monitoring system or maintaining it throughout its lifecycle? Request an assessment with Rees Scientific.

 

https://reesscientific.com/contact-us