# GAMP 5 Category 4 vs Category 5: what your software vendor must prove

> Configured vs custom software under GAMP 5: the classification, a side-by-side table, why it changes CSV effort, and the evidence a vendor must provide to claim Category 4.

- Type: Article · Jul 2026 · 6 pages · 6 min read
- Author: Adam Karpiński, Synlogica
- Canonical: https://synlogica.ai/resources/gamp-5-category-4-vs-5/

## 1. The short answer

**GAMP 5 Category 4** is *configured* software — a commercial product you set up with parameters, rules and workflows, without changing its code. **Category 5** is *custom (bespoke)* software — code written specifically for you. The practical difference is validation effort and risk: Category 5 requires you to validate the code itself (design reviews, code review, structural testing), while Category 4 lets you rely on the supplier's product lifecycle and focus your validation on **your configuration and its intended use**.

**Bottom line** The line between Cat 4 and Cat 5 is drawn by one question: did anyone write bespoke code for your instance? Configuration within a validated product is Cat 4. New code — custom modules, bespoke calculations, scripts that change behaviour — pulls that scope into Cat 5.

## 2. The GAMP 5 software categories

GAMP 5 (Second Edition, 2022) classifies computerised systems by how they are built, because that drives the risk-based validation approach:

| Category | What it is | Example | |

| 1 | Infrastructure software | Operating systems, databases, middleware | |

| 3 | Non-configured (used as-is) | Off-the-shelf tools used with default settings | |

| 4 | **Configured** | LIMS, MES, ERP, QMS — set up with your parameters and rules | |

| 5 | **Custom / bespoke** | Software (or modules) coded specifically for your process | |

(Category 2, firmware, was retired in GAMP 5 First Edition and does not appear in current classification.)

## 3. Category 4 vs Category 5 — side by side

| Aspect | Category 4 (configured) | Category 5 (custom) | |

| Code origin | Supplier's validated product | Written for your instance | |

| Supplier leverage | Rely on supplier lifecycle + audit | You own more of the lifecycle | |

| Design reviews | Configuration specification | Full design + code reviews | |

| Testing focus | Configuration & intended use (IQ/OQ/PQ) | Structural + functional, incl. code paths | |

| Change control | Re-verify affected configuration | Re-validate affected code | |

| Typical effort | Lower, if supplier evidence is strong | Higher | |

## 4. Why the classification changes your CSV effort

Classification is not paperwork — it decides how much you must prove yourself. A Category 4 product lets you **leverage the supplier's development and testing evidence** (via a supplier audit and their validation pack), so your on-site validation concentrates on whether *your configuration* does what you intend. Misclassifying a Cat 4 product as Cat 5 wastes effort; misclassifying a Cat 5 build as Cat 4 leaves untested code in a GxP decision path — the kind of gap a warning letter is written about.

The subtlety GAMP 5 Second Edition stresses: **configuration and customisation can coexist in one system**. A configured product with a bespoke calculation module is Category 4 for the configured parts and Category 5 for the custom module. Classify by component, not by the product label on the box.

## 5. What a vendor must prove for Category 4

If a supplier claims their product is Category 4 configurable software, ask for the evidence that lets you rely on it:

- A **documented product development lifecycle** (SDLC) you can audit.

- A **validation / qualification pack**: URS-to-test traceability, IQ/OQ scripts, release testing.

- A clear **configuration vs customisation boundary** — what you set up vs what would require new code.

- **Version-controlled, reproducible** behaviour — the same inputs and versions produce the same output, for the auditor.

- A **supplier audit** route (on-site or documented) so you can qualify them as a supplier.

This is the standard [Synlogica Terminus](https://synlogica.ai/) is built to: its Quality module (Terminus M4) is designed and documented as **GAMP 5 Category 4 configurable software** — configured with your SOPs, rules and thresholds, with a supplier validation pack and version-pinned, reproducible decision packages. The classification rationale and the validation approach are set out in our [GAMP 5 Category 4 classification white paper](https://synlogica.ai/resources/gamp-5-cat-4/).

## 6. FAQ

### Can one system be both Category 4 and Category 5?

Yes. GAMP 5 classifies by component. A configured product (Cat 4) that includes a bespoke module or custom calculation is Cat 5 for that module. Validate each part according to its own category rather than forcing one label on the whole system.

### Does Category 4 mean less validation?

It usually means *less duplicated* validation: you leverage the supplier's lifecycle evidence and focus on your configuration and intended use. The total rigor is risk-based — a high-impact GxP decision still demands thorough IQ/OQ/PQ, just not re-testing the supplier's code.

### Where do LLMs / AI features fall?

An AI/ML component that influences a GxP decision needs specific governance beyond the category label — data, model versioning and change control. This is why Synlogica keeps no LLM in the decision loop and is pursuing ISO 42001 for the AI-assisted extraction layer separately.

## 7. References

- ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition (2022).

- EU GMP Annex 11 — Computerised Systems.

- 21 CFR Part 11 — Electronic Records; Electronic Signatures.

- ISPE GAMP Good Practice Guides — Records & Data Integrity.
