What Happens When Medical Device Manufacturers Skip the GAMP Process
Skipping the GAMP process in medical device manufacturing automation doesn’t eliminate costs — it relocates them. Change orders, validation remediation, IQ/OQ/PQ delays, and FDA 483 observations are the standard outcomes when equipment is procured without the documentation structure GAMP requires. The costs arrive later and are harder to contain than the costs of doing it correctly from the start.
- Skipping GAMP doesn’t save money — it moves costs downstream to change orders and validation remediation
- The most common root cause of over-budget automation projects is an incomplete URS
- FDA’s updated Quality Management System Regulation (QMSR, 21 CFR Part 820, effective February 2026) didn’t make documentation requirements looser
- Every step of the GAMP process exists because a predictable failure mode occurs without it
Most manufacturers who decide to run an automation project without following a GAMP process aren’t trying to cut corners on compliance. They’re trying to move faster. They think the documentation is overhead that slows down procurement. Get the vendor started first, sort out the paperwork as the project progresses.
I’ve seen this reasoning many times across 96+ equipment procurement projects in medical device manufacturing. And I’ve seen where it leads.
The GAMP process exists because every step without it has a predictable, documented failure mode. This post covers four of the most common ones — not as a warning, but as a practical account of what actually happens on projects where the process gets skipped. If any of these patterns look familiar, the GAMP Documentation Services framework built at Gen-Probe and refined across 96+ projects was designed to prevent exactly them.
The Assumption Most Manufacturers Make
The assumption is that GAMP documentation is a compliance exercise — something the quality team needs, something that satisfies FDA, something required by the standard but not directly connected to whether the machine runs correctly or the project comes in on budget.
That assumption is wrong. But it’s understandable, because the connection between a properly written URS and on-time, on-budget delivery isn’t obvious until you’ve seen what happens when the URS is wrong.
Here’s the connection: the URS is what vendors quote against. The URS is what gets tested at FAT. The URS is what the trace matrix links through to IQ/OQ/PQ. Every downstream step of the project executes against whatever the URS says. When the URS is incomplete, vague, or assembled after vendor selection, every subsequent step has the same gaps — and each gap costs something.
The GAMP process isn’t an alternative to fast. It’s the process that produces fast outcomes, because it defines requirements before procurement begins instead of after the machine is built.
What Actually Goes Wrong — Four Failure Modes
These aren’t hypotheticals. They’re patterns I’ve seen repeatedly across 96+ projects. Each one traces back to a specific step in the GAMP process that was skipped or compressed.
The Vague URS That Produces Three Incomparable Quotes
The manufacturer sends an RFQ to three vendors. The RFQ describes the product, the production rate, and the general intent. The quotes come back at $380k, $690k, and $1.1M. Leadership asks engineering which one to pick. Engineering can’t answer because the quotes aren’t scoped to the same thing.
The $380k vendor didn’t include vision inspection — it wasn’t specified in the RFQ. The $1.1M vendor added $200k in contingency for requirements that weren’t defined clearly enough to quote against. The $690k vendor is somewhere in between, but nobody knows where.
Without a properly written URS, the vendor selection is a comparison of assumptions, not a comparison of capabilities. The manufacturer picks based on price — or on relationship — and the gaps in the requirements surface later as change orders.
A change order is a requirement that wasn’t in the URS. Every change order on a medical device automation project is traceable to something that wasn’t defined before the vendor started building. The average mid-size automation project running without a complete URS accumulates multiple change orders. Each one costs time, costs money, and costs the relationship between manufacturer and vendor.
FDA updated 21 CFR Part 820 to the Quality Management System Regulation (QMSR), effective February 2026, harmonized with ISO 13485:2016. The documentation standards didn’t change in a direction that makes this easier. Process validation failures under §820.75 remain among the most frequently cited 483 observations in FDA inspections of medical device manufacturers.
The FAT That Becomes a Demo
The vendor invites the manufacturer to Factory Acceptance Testing. The team flies out, watches the machine run, and signs off. The machine ships. Everything looked fine.
Three months later, during IQ/OQ/PQ, the qualification team discovers six requirements from the URS that weren’t tested at FAT. Two of them, the machine doesn’t meet. The vendor is back to resolve deficiencies on installed equipment, at the manufacturer’s facility, on the manufacturer’s timeline. The IQ/OQ/PQ timeline slips by eight weeks.
This happens because a FAT without a test protocol is a demo. A properly executed FAT runs every requirement in the URS against a documented test protocol, with defined acceptance criteria and a punch list for everything that doesn’t pass. The FAT documentation feeds the trace matrix. The trace matrix feeds IQ/OQ/PQ.
When the FAT is a demo, the trace matrix has gaps. When the trace matrix has gaps, IQ/OQ/PQ has gaps. When IQ/OQ/PQ has gaps, the quality team can’t stand behind the documentation when FDA shows up.
The FAT/SAT Services structure MEPSCo uses starts with a test protocol built from the URS, executed at the vendor’s facility, with punch list items tracked to resolution before the machine ships. That protocol is developed before the travel date — not assembled at the vendor’s facility on the morning of FAT.
The Validation Documentation Assembled After the Fact
The machine is built. The machine is installed. The team starts IQ/OQ/PQ. At some point during qualification, someone asks: “Do we have a validation plan?” Nobody does. The validation plan gets written while qualification is underway.
This is more common than it sounds. On projects that run without the GAMP process, documentation often gets assembled to catch up with what’s already happened — rather than built to define what will happen. The IQ/OQ/PQ protocols reference a URS that was written after vendor selection. The trace matrix links requirements to FAT tests that weren’t formally documented. The validation plan describes the qualification approach after the qualification has started.
Documentation assembled after the fact is documentation that the quality team can’t stand behind completely — because the team knows, and FDA may discover, that the documentation was assembled to reflect decisions already made, not to define and verify requirements before they were built.
GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems (ISPE, second edition 2022) states the principle directly: quality is built into the system at each stage of the lifecycle, not tested in afterward. That’s not just a compliance statement. It’s a description of why retrospective documentation costs more than prospective documentation — and why IQ/OQ/PQ runs faster when the documentation was built correctly from the URS forward.
The Equipment That Can’t Be Modified Without a Change Order
The machine is validated and running. Eighteen months later, the product changes. A component dimension shifts. The fill volume tolerance tightens. The reagent formulation is updated.
On a machine procured with a complete GAMP documentation package — a URS that defined requirements specifically and a trace matrix that linked them through qualification — the change control process is manageable. The change is evaluated against the documented requirements. The affected validation steps are identified. The re-qualification scope is defined and executed.
On a machine procured without that documentation, every change requires reconstructing what was originally required, what was tested, and what was qualified — because the documentation doesn’t exist to answer those questions clearly. Each change costs significantly more than it should, because the baseline documentation that would make change control straightforward was never created.
Maintainability is built in at the design stage or paid for later. The same is true of documentation.
What the GAMP Process Prevents — Specifically
Generic “benefits of GAMP” content lists things like “improved compliance” and “enhanced traceability.” Those are true. They’re also not useful for a Director of Manufacturing trying to decide whether to engage a GAMP documentation specialist on an upcoming project.
Here’s what the process prevents specifically:
- Incomparable vendor quotes. A complete Budgetary URS produces quotes scoped to the same requirements. Vendors quote to defined criteria, not to their assumptions. The lowest bid can be evaluated against actual capability instead of against a vague scope.
- Change orders. A change order is a requirement that wasn’t defined upfront. A complete URS, with every requirement specific and verifiable, eliminates the documentation gaps vendors use to issue change orders. The DOD pandemic project — $150M in equipment validated in one year, with a reduced team, during COVID — produced no change orders because the URS was complete before any vendor was contacted.
- IQ/OQ/PQ delays. When the URS is complete, the trace matrix is started at the URS stage, and FAT is executed against a documented protocol, IQ/OQ/PQ runs from a complete documentation baseline. Qualification runs faster when there’s nothing to reconstruct. On the replicate machines for the DOD project, three additional 200 PPM lines were qualified in record time because the original URS and GAMP documentation were thorough enough that replicate qualification required minimal additional engineering involvement.
- 483 observations on documentation. The trace matrix, the validation plan, the FAT documentation — these are what FDA inspectors evaluate. When they’re complete, the inspection conversation is about operations, not about gaps in the documentation chain.
A Word on the Regulatory Environment in 2026
FDA published the final rule updating 21 CFR Part 820 to the Quality Management System Regulation (QMSR) in February 2024, with an effective date of February 2, 2026. The QMSR harmonizes FDA’s quality system requirements with ISO 13485:2016. Equipment validation requirements under §820.75 remain in place. Failure to validate processes that can’t be fully verified by inspection or test is still one of the most frequently cited 483 observations in medical device manufacturing inspections.
The regulatory environment didn’t become more lenient. The documentation that supports GAMP compliance — the URS, the trace matrix, the FAT and SAT documentation, the IQ/OQ/PQ protocols — is still what FDA inspectors evaluate when they assess whether a manufacturer’s equipment was properly qualified.
Getting that documentation right from the beginning is still the correct approach. That’s what the GAMP process is for.
Every week a project runs without defined requirements is a week of vendor assumptions building into the machine. Those assumptions don’t surface as problems during procurement — they surface as change orders, FAT punch lists, and qualification delays.
Common Questions
What is the GAMP process in medical device manufacturing?
GAMP (Good Automated Manufacturing Practice) is a framework developed by the International Society for Pharmaceutical Engineering (ISPE) that defines how automated manufacturing equipment should be specified, procured, validated, and maintained in regulated industries. In medical device manufacturing, the GAMP process governs how equipment requirements are documented in a URS, how vendors are selected and managed, how acceptance testing is executed at FAT and SAT, and how IQ/OQ/PQ qualification is performed and documented.
Why do change orders happen on medical device automation projects?
Change orders happen when a requirement wasn’t defined in the URS before the vendor started building. Vendors quote against what’s in the requirements document. When requirements are incomplete or vague, vendors make assumptions — and each assumption that doesn’t match what the manufacturer actually needed becomes a change order. A complete URS eliminates the gaps vendors use to issue change orders.
How does skipping GAMP documentation affect IQ/OQ/PQ?
IQ/OQ/PQ builds on the FAT and SAT documentation, which builds on the URS and trace matrix. When upstream documentation is missing or incomplete, the qualification team has to reconstruct requirements, reconcile undocumented FAT results, and build a trace matrix retroactively — all during qualification, on the manufacturer’s timeline. Qualification runs slower and the resulting documentation is harder to defend during FDA inspection.
Is GAMP compliance required by FDA for medical device manufacturers?
GAMP 5 itself is a voluntary industry guideline, not a regulation. The FDA regulations that apply are 21 CFR Part 820 — now the Quality Management System Regulation (QMSR), effective February 2026 — which requires that processes be validated and that the validation be documented. GAMP 5 provides the methodology for meeting those requirements. Failure to validate processes in accordance with §820.75 is one of the most frequently cited 483 observations in medical device manufacturer inspections.
What’s the difference between following GAMP and just having a quality team?
A quality team reviews documentation. The GAMP process defines what documentation gets created, when, and how it connects to the equipment requirements. A quality team reviewing documentation that doesn’t exist, or that was assembled retroactively, is in a difficult position during an FDA audit — because they can attest that the documents exist but can’t attest that the process they describe was followed from the beginning. GAMP documentation is built prospectively, before and during procurement, so the quality team can stand fully behind it.
How long does it take to set up the GAMP documentation process on a new project?
The CRD and stakeholder interviews can happen in the first week of an engagement. The Budgetary URS — complete enough to get comparable vendor quotes — typically takes 2–4 weeks depending on project complexity and process definition. The full GAMP documentation process runs alongside the procurement project from that point. Getting started correctly at the beginning of the project is the most important timing decision.
If you’re starting an automation project or have one that’s already underway, the Manufacturing Automation Assessment is the right starting point.
Download the GAMP Roadmap to see the 8-step process and where each document fits.