How do I classify a system into a GAMP 5 category, and what does that mean for validation scope?
The category follows the degree of configuration and custom code: category 3 is standard software used unconfigured or in its default configuration, 4 is configurable (LIMS, MES, ERP), 5 is custom-built. The higher the category and the GxP impact, the more testing you own and the less you lean on the supplier. We classify in step 01 and record the rationale, because an inspector asks not for the number but for why.
Does a system with low GxP impact still need validation?
The GxP impact assessment sets the scope, not whether you validate. A system with no impact on product quality, patient safety or data integrity needs only a documented assessment and rationale. A system with indirect impact gets a proportionally smaller package: risk assessment, key tests, RTM. The most common finding is no evidence that the assessment was ever done.
GAMP 5 or CSA — do you have to choose?
No. They are not competing approaches. CSA is FDA guidance for software used in medical device production and quality systems (21 CFR 820), finalised 24 September 2025; it does not bind drug manufacturers. GAMP 5 2nd Edition (2022) already carries the same critical, risk-based thinking and includes an appendix aligning itself with CSA. Valready works to GAMP 5 (2nd Ed.): it defines the life cycle, the system category and the amount of testing proportionate to risk.
Can validation documentation generated by AI meet GMP requirements?
It can, under human oversight. In Valready, AI prepares drafts only. In the sprint our CSV expert reviews them before they reach you; in Workspace your team runs the review, and the tool will not close a requirement's coverage until a human accepts the test. Formal approval happens in your QMS, by your Quality Unit. This follows the human-in-the-loop principle of the draft EU GMP Annex 22. AI never approves anything on its own.
What does the draft Annex 22 mean in practice for using AI in validation documentation?
The draft Annex 22 (consultation closed in 2025, finalisation pending) expects a defined intended use for the model, validation and change control, human oversight of outputs, and data transparency. For documentation: an AI output stays a draft until a human has reviewed it, and that review must be documented: who, when and what changed. If your QMS has no procedure for AI use, write one before the first project.
What does an RTM have to look like to hold up in an inspection?
Every URS requirement needs at least one test with a result and a reference to the evidence, and every test needs the requirement it covers. Inspectors check the gaps in both directions: requirements without a test and tests without a requirement. Typical findings: an RTM written after testing, version drift between URS and protocol, requirements “covered” by a test that checks something else. Valready keeps that consistency during the work, not at the end.
Our SaaS vendor shipped a new release — do I have to revalidate everything?
Not everything, but you must show the change was assessed. You need an impact assessment of the change on GxP requirements and functions, regression testing of what it touches, and a change-control record. With frequent SaaS releases the supplier agreement matters most: advance notice of changes and access to the vendor's test documentation. Periodic review catches what slipped between releases.
How far can I rely on supplier documentation instead of testing myself?
GAMP 5 explicitly encourages leveraging supplier work, provided you have a documented supplier assessment (audit, questionnaire or desk assessment) and have checked that their testing covers your requirements. You test what is specific to your configuration, process and data yourself. Citing supplier documents without a supplier assessment is one of the more common findings.
Can I take Workspace on its own, without a validation sprint?
Yes. Workspace is a separate subscription product: you receive the tool and run the documentation with your own team. The validation sprint is optional and bought separately. Workspace access is granted by name, with no self-registration. Access control is designed for the Annex 11 requirements.
Do you guarantee passing an audit or inspection?
No. Nobody can honestly promise that. We provide a documentation structure that traces each requirement to its test and evidence; final compliance depends on the scope, the context and what your Quality Unit approves.
What about the security of our sensitive documentation?
Client data is segregated and never used to train models. The production environment runs in the European Union (Azure). The tool has access control, an audit trail and versioning.
How do we start?
With a conversation about one system. The first step is usually a fixed-price CSV documentation sprint, followed, if it makes sense, by maintenance in Workspace.