Contents
1. The short answer
GAMP 5 Category 4 is configured software — a commercial product you set up with parameters, rules and workflows, without changing its code. Category 5 is custom (bespoke) software — code written specifically for you. The practical difference is validation effort and risk: Category 5 requires you to validate the code itself (design reviews, code review, structural testing), while Category 4 lets you rely on the supplier's product lifecycle and focus your validation on your configuration and its intended use.
2. The GAMP 5 software categories
GAMP 5 (Second Edition, 2022) classifies computerised systems by how they are built, because that drives the risk-based validation approach:
| Category | What it is | Example |
|---|---|---|
| 1 | Infrastructure software | Operating systems, databases, middleware |
| 3 | Non-configured (used as-is) | Off-the-shelf tools used with default settings |
| 4 | Configured | LIMS, MES, ERP, QMS — set up with your parameters and rules |
| 5 | Custom / bespoke | Software (or modules) coded specifically for your process |
(Category 2, firmware, was retired in GAMP 5 First Edition and does not appear in current classification.)
3. Category 4 vs Category 5 — side by side
| Aspect | Category 4 (configured) | Category 5 (custom) |
|---|---|---|
| Code origin | Supplier's validated product | Written for your instance |
| Supplier leverage | Rely on supplier lifecycle + audit | You own more of the lifecycle |
| Design reviews | Configuration specification | Full design + code reviews |
| Testing focus | Configuration & intended use (IQ/OQ/PQ) | Structural + functional, incl. code paths |
| Change control | Re-verify affected configuration | Re-validate affected code |
| Typical effort | Lower, if supplier evidence is strong | Higher |
4. Why the classification changes your CSV effort
Classification is not paperwork — it decides how much you must prove yourself. A Category 4 product lets you leverage the supplier's development and testing evidence (via a supplier audit and their validation pack), so your on-site validation concentrates on whether your configuration does what you intend. Misclassifying a Cat 4 product as Cat 5 wastes effort; misclassifying a Cat 5 build as Cat 4 leaves untested code in a GxP decision path — the kind of gap a warning letter is written about.
The subtlety GAMP 5 Second Edition stresses: configuration and customisation can coexist in one system. A configured product with a bespoke calculation module is Category 4 for the configured parts and Category 5 for the custom module. Classify by component, not by the product label on the box.
5. What a vendor must prove for Category 4
If a supplier claims their product is Category 4 configurable software, ask for the evidence that lets you rely on it:
- A documented product development lifecycle (SDLC) you can audit.
- A validation / qualification pack: URS-to-test traceability, IQ/OQ scripts, release testing.
- A clear configuration vs customisation boundary — what you set up vs what would require new code.
- Version-controlled, reproducible behaviour — the same inputs and versions produce the same output, for the auditor.
- A supplier audit route (on-site or documented) so you can qualify them as a supplier.
This is the standard Synlogica Terminus is built to: its Quality module (Terminus M4) is designed and documented as GAMP 5 Category 4 configurable software — configured with your SOPs, rules and thresholds, with a supplier validation pack and version-pinned, reproducible decision packages. The classification rationale and the validation approach are set out in our GAMP 5 Category 4 classification white paper.
6. FAQ
Can one system be both Category 4 and Category 5?
Yes. GAMP 5 classifies by component. A configured product (Cat 4) that includes a bespoke module or custom calculation is Cat 5 for that module. Validate each part according to its own category rather than forcing one label on the whole system.
Does Category 4 mean less validation?
It usually means less duplicated validation: you leverage the supplier's lifecycle evidence and focus on your configuration and intended use. The total rigor is risk-based — a high-impact GxP decision still demands thorough IQ/OQ/PQ, just not re-testing the supplier's code.
Where do LLMs / AI features fall?
An AI/ML component that influences a GxP decision needs specific governance beyond the category label — data, model versioning and change control. This is why Synlogica keeps no LLM in the decision loop and is pursuing ISO 42001 for the AI-assisted extraction layer separately.
7. References
- ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition (2022).
- EU GMP Annex 11 — Computerised Systems.
- 21 CFR Part 11 — Electronic Records; Electronic Signatures.
- ISPE GAMP Good Practice Guides — Records & Data Integrity.