At a glance
- GxP is the umbrella for the “Good x Practice” disciplines: GCP (clinical), GLP (laboratory), GMP (manufacturing), GDP (distribution), and GVP (pharmacovigilance). The “x” is the variable.
- The disciplines differ in what they govern, but in a software-run operation they converge on the same three controls: computer system validation, data integrity (ALCOA+), and electronic records and signatures (Part 11 / Annex 11).
- “Are we GxP compliant?” really means “do our systems and records hold up under inspection?” That reframing is the point of this guide.
- There is no single GxP certificate you pass. GxP is a family of expectations enforced by inspectors against specific regulations, not one certifiable standard.
- A small team’s practical job is to get those three shared controls right and keep the records and oversight organized; the discipline-specific depth lives in the dedicated guides.
Search “GxP compliance” and most pages spell out the acronyms (GCP, GLP, GMP, GDP, GVP) and stop. That leaves you with vocabulary, not understanding. The more useful frame for the digital era is this: the five disciplines govern different activities, but in any software-run operation they lean on the same machinery, validated systems, trustworthy data, and controlled electronic records. Understand that throughline and “GxP compliant” stops being a mystery.
This guide decodes the umbrella, explains what each discipline governs, then shows the shared backbone the disciplines converge on, clarifies that there is no single GxP certification, and offers a practical checklist. It is an orienting pillar: it summarizes and hands off, routing CSV mechanics, Part 11 detail, ALCOA depth, and GCP specifics to their own guides rather than re-teaching them.
What is GxP?
GxP stands for “Good x Practice,” where the “x” is a placeholder for a discipline (Clinical, Laboratory, Manufacturing, Distribution, Pharmacovigilance). Collectively, the GxP disciplines are the quality standards and regulatory expectations that govern the development, testing, manufacture, distribution, and monitoring of medical products, all aimed at ensuring product quality, data integrity, and patient safety. “GxP compliance” is the state of meeting those expectations for the activities you perform.
The GxP family: what each discipline governs
| Discipline | Governs | Core concern |
|---|---|---|
| GCP — Good Clinical Practice | Human-subject clinical trials | Participant safety and reliable trial data |
| GLP — Good Laboratory Practice | Non-clinical safety (lab) studies | Quality and integrity of preclinical data |
| GMP — Good Manufacturing Practice | Production of medical products | Consistent, quality manufacturing |
| GDP — Good Distribution Practice | The supply chain | Product integrity through distribution |
| GVP — Good Pharmacovigilance Practice | Post-market safety | Detecting and acting on adverse events |
GCP — Good Clinical Practice
GCP governs the conduct of clinical trials in human participants. ICH E6(R3) frames it as an ethical and scientific quality standard whose objective is to protect participants’ rights, safety, and well-being and to assure the reliability of trial results (Introduction). It is the discipline most relevant to running a trial.
GLP — Good Laboratory Practice
GLP governs non-clinical safety studies, the laboratory work (often animal and in-vitro) that supports a product’s safety before and alongside human trials. Its concern is the quality and integrity of that preclinical data.
GMP — Good Manufacturing Practice
GMP governs the manufacture of medical products, ensuring they are consistently produced to quality standards. It is the most mature GxP discipline and the origin of much data-integrity thinking.
GDP — Good Distribution Practice
GDP governs the distribution and supply chain, ensuring product integrity (storage, transport, traceability) from manufacture to patient.
GVP — Good Pharmacovigilance Practice
GVP governs post-market safety monitoring, the systems and processes for detecting, assessing, and acting on adverse events once a product is in use.
What GxP compliance actually requires (the shared backbone)
Here is the information the acronym lists omit. However different the disciplines are in subject, a modern, software-run operation meets them through three shared controls. Get these right and you have addressed the bulk of what an inspector checks across disciplines.
Computer system validation (systems do what they should, provably)
The systems that run regulated activities must be validated, demonstrably fit for their intended use. EU Annex 11, the computerised-systems standard for GMP-regulated activity, states the principle directly: the application should be validated and the IT infrastructure qualified, with risk management applied throughout the system lifecycle and the extent of validation based on a documented risk assessment (Annex 11, Principle and § 1). The depth of how to validate lives in the CSV hub; the GxP point is that validated systems are a shared requirement.
Data integrity and ALCOA+ (records you can trust)
Across GxP, the data must be trustworthy. The MHRA’s data-integrity guidance frames this through ALCOA: data must be Attributable, Legible, Contemporaneous, Original, and Accurate, with the “+” adding Complete, Consistent, Enduring, and Available throughout the data lifecycle (Data Integrity Guidance and Definitions). Whether the data is clinical, laboratory, or manufacturing, those integrity attributes apply. The ALCOA guide covers the attributes in depth.
21 CFR Part 11 / Annex 11 (electronic records and signatures)
When the records are electronic, they fall under electronic-records rules: 21 CFR Part 11 in the US and EU Annex 11 in Europe. Annex 11 requires, for example, that changes to a computerised system be made only in a controlled manner per a defined procedure (§ 10) and that systems be periodically evaluated to confirm they remain valid (§ 11). The Part 11 guides cover the US rule’s record and signature requirements. The GxP point is that controlled electronic records are the third shared control.
The throughline: “GxP compliant” in a software-run operation means your systems are validated, your data has integrity, and your electronic records are controlled. Those three, not the acronym list, are where compliance is won or lost.
Is GxP a certification?
No, and this matters. There is no single “GxP certificate” you sit an exam for and pass. GxP is a family of expectations enforced by inspectors against specific underlying regulations (the GCP, GMP, and other rules and guidances). You demonstrate compliance through your validated systems, your data integrity, your controlled records, and your documented procedures, examined in an inspection, not through a one-time certification. Anyone selling “GxP certification” as a pass/fail badge is misrepresenting how it works.
A practical GxP compliance checklist
For a small team facing “show me your GxP controls,” a starting checklist (each item routes to a sibling for depth):
- Systems validated for their intended use, with current validation evidence (see the CSV hub).
- Data integrity controls in place: attributable, contemporaneous, complete, with audit trails (see the ALCOA and audit-trail guides).
- Electronic records controlled under Part 11 / Annex 11: access control, audit trails, signatures where used (see the Part 11 guides).
- Procedures (SOPs) written and followed for the regulated activities.
- Training records showing people are qualified for their tasks.
- Vendor oversight documented for any delegated, GxP-relevant systems or activities.
- Change control that re-assesses validated state and record integrity after changes.
Treat this as an orientation, not the deep work; each item has a discipline behind it.
Where to go deeper
This page orients; the depth lives in the siblings: the CSV hub for validation, the 21 CFR Part 11 guides for electronic records and signatures, the ALCOA and audit-trail guides for data integrity, and the GCP explainer for clinical-specific obligations.
A light tooling note: purpose-built clinical software can help a small team keep GxP-relevant records and oversight organized (audit trails, role-based access, documented oversight). TrialTrack is one such clinical project management tool; its vendor describes Part 11-aligned capabilities, which is TrialTrack’s own claim, and no software makes a team GxP compliant. Compliance is the team’s, demonstrated to an inspector.
Frequently asked questions
What does GxP stand for, and what is the “x”? “Good x Practice,” where the “x” is the discipline: Clinical (GCP), Laboratory (GLP), Manufacturing (GMP), Distribution (GDP), or Pharmacovigilance (GVP).
What are the main GxP disciplines and what does each govern? GCP governs human-subject trials, GLP non-clinical lab studies, GMP manufacturing, GDP the supply chain, and GVP post-market safety.
What does GxP compliance require across disciplines? In a software-run operation, three shared controls: computer system validation, data integrity (ALCOA+), and controlled electronic records and signatures (Part 11 / Annex 11).
Is there a GxP certification? No. GxP is a family of expectations enforced by inspectors against specific regulations, not a single certifiable standard you pass.
How do CSV, data integrity, and Part 11 relate to GxP? They are the shared backbone: validated systems, trustworthy data, and controlled electronic records are what “GxP compliant” concretely means for the systems and records a team runs.
The bottom line
GxP is the umbrella over GCP, GLP, GMP, GDP, and GVP, and the “x” is just the discipline. The disciplines govern different activities, but in a software-run operation they converge on three controls: computer system validation, data integrity, and controlled electronic records. There is no single GxP certificate, so “are we GxP compliant?” really means “do our validated systems and trustworthy records hold up under inspection?” Get the three shared controls right, and you have the backbone of GxP compliance.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
