
Computer system validation has a bad reputation: too often it stands for stacks of test scripts that nobody reads. The second edition of GAMP 5 clears this up and brings the actual purpose to the fore, namely robust data integrity at a proportionate level of effort. The framework is not new, but it is thought through more consistently.
The core remains the risk-based approach. Three questions govern it: what does a failure mean for the patient, for product quality, for the integrity of the data? Where the answer is harmless, work stays lean. Where it is not, testing goes deep. The typical mistake in projects is not too little effort, but effort spread evenly.
Assignment to the GAMP software categories determines the path: infrastructure (1), non-configured standard software (3), configured products (4) and bespoke development (5). The higher up the scale, the more can rest on the supplier's work, provided a qualified assessment supports it.
Three areas carry new weight. Iterative and agile development is treated as the normal case rather than an exception. Cloud and service models get their own space, including the question of what the provider delivers and what remains your own responsibility. And data integrity is no longer a chapter off to one side, but a design requirement. The FDA is pursuing the same direction with Computer Software Assurance.
The most important change is cultural. What is called for is engineers who think, not form-fillers. A test case that exists only because the template has a line for it costs time and proves nothing. Conversely, a brief, well-argued check is worth more than twenty pages of evidence about a non-critical function. What is required is the rationale, not the volume.
Less documentation, more data integrity: this is not a contradiction, but the goal.
Validation does not end with PQ. Changes run through change control, periodic review checks whether the assumptions still hold, and backup together with restore must not be asserted but tested. The end belongs to it as well: when a system is replaced, it has to be clear how the data stays readable across the retention period. Replacements fail on that more often than on the migration itself.
Abdel R. Majadi, founder and Engineering Lead of Vispact GmbH: more than ten years of experience in running GMP cleanroom operations, focused on qualification to Annex 15, CSV to GAMP 5 and data integrity to ALCOA+.
More about the teamIf a topic from this article is currently on your plant's agenda, we will discuss it concretely in an initial consultation.
30 minutes, no obligation. Reply within one working day, directly from engineering.