Compliance

What Is GxP? A Plain-English Guide to GMP, GLP and GCP

GxP explained without the jargon: what the letters mean, which rules apply to which work, who enforces them, and what "being GxP compliant" actually requires of a system or a team.

2026-09-20Cybroscape Technologies10 min read
Key takeaway

GxP explained without the jargon: what the letters mean, which rules apply to which work, who enforces them, and what "being GxP compliant" actually requires of a system or a team.

GxP is an umbrella term for the "Good Practice" quality regulations that govern life sciences. The x is a placeholder: swap in M for Manufacturing and you get GMP, L for Laboratory gives GLP, C for Clinical gives GCP, D for Distribution gives GDP. They are separate rulebooks written by regulators at different times for different activities, and GxP is simply the collective noun for all of them.

What they share is a single underlying demand: if you make, test, study or distribute a medicine or a medical device, you must be able to prove what you did, who did it, when, and that it was done correctly — using records created at the time, not reconstructed afterwards. Nearly every GxP requirement is a specific expression of that one idea.

This guide covers what the letters mean, which rules apply to which work, who enforces them, and what "GxP compliant" actually requires of a system or a team. For the software dimension see GxP software, and for how artificial intelligence fits into regulated work see GxP AI.

What the letters mean

  • GMP — Good Manufacturing Practice. Governs how a product is made: facilities, equipment, materials, batch records, in-process controls, release. The most operationally demanding of the set, because it applies continuously to everything leaving your site.
  • GLP — Good Laboratory Practice. Governs non-clinical safety studies — the toxicology and safety pharmacology work done before a compound reaches humans. Narrower than most people assume: routine QC testing in a manufacturing lab is GMP, not GLP.
  • GCP — Good Clinical Practice. Governs clinical trials: protocol adherence, informed consent, investigator responsibilities, source data, safety reporting. Protecting trial subjects is its first purpose; data credibility is its second.
  • GDP — Good Distribution Practice. Governs the journey from release to patient: storage conditions, cold chain, transport, counterfeit prevention, recall capability.
  • GVP — Good Pharmacovigilance Practice. Governs safety monitoring after a product is on the market: adverse event collection, signal detection, periodic safety reporting.

A single company routinely operates under several at once. A biotech running a trial while manufacturing its own clinical supply is under GCP and GMP simultaneously, with different documentation expectations applying to the same week of work.

Who writes and enforces GxP rules

There is no single global GxP authority. Each region regulates its own market, and you must satisfy every regulator whose market you sell into.

  • United States — FDA. Rules live in the Code of Federal Regulations: 21 CFR Parts 210 and 211 for drug GMP, Part 820 for device quality systems, Part 58 for GLP, Part 312 for clinical trials, and 21 CFR Part 11 for electronic records and signatures.
  • European Union — EMA and national agencies. EudraLex Volume 4 carries GMP, with annexes for specific topics. Annex 11 covers computerised systems; Annex 22 addresses artificial intelligence.
  • United Kingdom — MHRA. Closely aligned with EU rules post-Brexit but independently enforced, with its own data integrity guidance.
  • International — ICH and PIC/S. ICH harmonises technical requirements across regions; PIC/S aligns inspection practice among member authorities.

The practical consequence: aim at the strictest applicable requirement rather than maintaining separate systems per region. Divergent regional quality systems are expensive to run and produce contradictions inspectors notice.

What GxP compliance actually requires

Beneath the detail, GxP compliance rests on a handful of durable principles. Almost every specific requirement you will encounter is one of these applied to a particular activity.

  • Write down what you do; do what you wrote down. Procedures exist before the work, are approved, and are followed. A process performed well but differently from its SOP is still a deviation.
  • Records are contemporaneous. Created as the work happens. Notes transcribed later from memory are not GxP records, however accurate.
  • Data integrity — ALCOA+. Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available. See data integrity services.
  • Qualified people. Training is documented, current, and specific to the task.
  • Controlled change. Nothing that affects product quality changes without assessment, approval and a record.
  • Validated systems. Any computerised system relied on for a GxP decision is shown to work as intended, and shown to still work over time. That is the subject of computer system validation.

What makes a system GxP-relevant

Not every system in a life sciences company falls under GxP. The test is function, not location. A system is GxP-relevant if it creates, modifies, stores or transmits data used to make a decision about product quality, patient safety or regulatory submission — or if it controls a process that affects those outcomes.

A LIMS holding release test results is GxP. A MES executing batch records is GxP. The payroll system is not. The ambiguity sits in the middle: a training system is GxP-relevant because training records are inspected; a document management system is GxP-relevant because it holds controlled procedures; a maintenance system is GxP-relevant because calibration status affects the validity of test results.

Getting this boundary right early matters more than most teams expect. Scope it too narrowly and you have unvalidated systems feeding regulated decisions. Scope it too broadly and you spend validation budget on systems no inspector will ever ask about. A structured GxP risk assessment is how you draw the line defensibly.

The most common misunderstandings

"GxP compliant" is not a property a product can have on its own. A vendor can supply a system capable of supporting compliance — audit trails, access control, electronic signatures. Compliance is achieved by how you configure, validate, and operate it. Any vendor selling you a "fully GxP compliant, no validation needed" product is describing something that does not exist.

Validation is not a one-off event. Systems drift. Configurations change, suppliers push updates, integrations move. Validated status is maintained through change control and periodic review, not achieved once at go-live.

More documentation is not more compliance. Volume is not the measure; traceability is. A lean, well-linked package that shows a reviewer how a requirement became a test and how that test passed is stronger than hundreds of pages nobody can navigate.

GxP does not forbid new technology. Cloud systems, automation and AI are all usable in regulated environments. They require assurance evidence proportionate to risk — which is a design problem, not a prohibition.

Where to start if GxP is new to you

  • Establish which disciplines apply to your work. A device company and a CRO have almost no overlap in daily obligations. GxP vs GMP vs GLP vs GCP breaks down the boundaries.
  • Inventory your systems and mark which are GxP-relevant, with a documented rationale for each. This inventory is usually the first thing an auditor asks for.
  • Fix data integrity before adding tools. A new system on top of undisciplined data practice inherits the problem and makes it faster.
  • Make training real. Read-and-understood records against an unread SOP are among the easiest findings for an inspector to generate.
  • Treat inspection readiness as a continuous state rather than a project. Preparing for a GxP audit covers what that looks like week to week.

Teams modernising this layer usually look at GxP software next, and increasingly at GxP AI for the documentation-heavy parts of validation and quality work.

Where to go next

Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.

what is gxpgxp meaninggxp definitiongxp explainedgxp compliance basicswhat does gxp stand for

Frequently Asked Questions

What does GxP stand for?+

GxP stands for 'Good Practice', where the x is a placeholder for a specific discipline. GMP is Good Manufacturing Practice, GLP is Good Laboratory Practice, GCP is Good Clinical Practice, GDP is Good Distribution Practice, and GVP is Good Pharmacovigilance Practice. GxP is the collective term for all of them.

What is GxP compliance in simple terms?+

GxP compliance means you can prove what you did, who did it, when, and that it was done correctly — using records created at the time rather than reconstructed afterwards. In practice it requires written procedures that are actually followed, contemporaneous records, trained people, controlled change, and validated systems for anything supporting a regulated decision.

Who enforces GxP regulations?+

There is no single global authority. The FDA enforces GxP in the United States through the Code of Federal Regulations, the EMA and national agencies enforce it in the European Union through EudraLex, and the MHRA enforces it in the UK. ICH and PIC/S harmonise requirements and inspection practice across regions. You must satisfy every regulator whose market you sell into.

How do I know if a system is GxP-relevant?+

A system is GxP-relevant if it creates, modifies, stores or transmits data used to decide something about product quality, patient safety or a regulatory submission — or if it controls a process affecting those outcomes. A LIMS holding release results is GxP-relevant; payroll is not. Document the rationale for systems you exclude as well as those you include, because auditors ask about exclusions.

Can a software product be 'GxP compliant' on its own?+

No. A vendor can supply a system capable of supporting compliance — audit trails, access control, electronic signatures — but compliance is achieved through how you configure, validate and operate it. Any vendor claiming their product is fully GxP compliant with no validation required is describing something that does not exist.

Next step

Bring a system. We'll show you the package.