Skip to content
Regulated software7 min read

EU GMP Annex 11 explained: computerised systems, section by section

EU GMP Annex 11 in plain English: what each section asks of computerised systems, how it compares with 21 CFR Part 11, and what to check in your software.

Regulated software
Key takeaways
  • Annex 11 is the EU GMP guideline for computerised systems used in GMP activities; PIC/S applies an equivalent annex.
  • Its 17 sections cover the whole life cycle: risk, people, suppliers, validation, data, audit trails, change, security, e-signatures, continuity and archiving.
  • Compared with Part 11 it says more about suppliers, risk management, periodic evaluation and business continuity, and explicitly asks for a reason for change.
  • A revised draft was released for consultation in July 2025; check its status, but the 2011 text applies until a final version is adopted.

EU GMP Annex 11 is the European guideline for computerised systems used in GMP-regulated work. It says such systems must be validated, managed with documented risk assessment, supported by qualified suppliers, and must protect data with audit trails, security, backups and controlled change. Replacing a manual step with software must not reduce product quality or control.

If you sell to the EU or are inspected by a PIC/S authority, Annex 11 is the reference your auditors will use. This guide goes through it section by section, then compares it with 21 CFR Part 11.

What Annex 11 is and where it applies

Annex 11, Computerised Systems, is part of EudraLex Volume 4, the EU guidelines for Good Manufacturing Practice. The current text came into operation on 30 June 2011. PIC/S member inspectorates apply an equivalent annex in the PIC/S GMP Guide, so its reach goes well beyond the EU.

It applies to every computerised system used as part of GMP activities: lab systems, quality systems, manufacturing and warehouse systems, and the IT infrastructure under them, which must be qualified. It works together with Chapter 4 on documentation, which covers records whatever medium they are kept in.

The principle is short: when a computerised system replaces a manual operation, there should be no loss of product quality, process control or quality assurance, and no increase in overall risk.

The 17 sections, in plain English

EU GMP Annex 11 sections and what they mean for software
SectionWhat it asksWhat to check in the software
1 Risk managementDocumented, justified risk assessment across the life cycleValidation depth and data-integrity controls follow the risk record
2 PersonnelProcess owners, system owners, QA and IT work together, with the right trainingRoles and responsibilities are defined
3 SuppliersFormal agreements; supplier assessment and audits based on riskSupplier documentation is available and reviewed
4 ValidationLife-cycle documents, system inventory, traceable URS, tested data migrationRequirements trace to tests; migrations are verified
5 DataBuilt-in checks for data exchanged electronicallyInterfaces validate what they send and receive
6 Accuracy checksAn extra check for critical data entered manuallySecond-person or system verification of key entries
7 Data storageData secured; backups taken; restore checked during validation and periodicallyTested backup and restore procedures
8 PrintoutsClear printed copies; batch-release prints show if data changedReports flag edits since original entry
9 Audit trailsRisk-based trail of GMP-relevant changes and deletions, with a reason, regularly reviewedOld and new values, reason and a review process
10 Change managementChanges made under a defined procedureConfiguration and code changes are controlled and recorded
11 Periodic evaluationSystems reviewed to confirm they remain valid and compliantA scheduled periodic review with evidence
12 SecurityPhysical and logical access control; access changes recordedUnique accounts, roles and an access-change log
13 Incident managementIncidents reported, assessed and their root cause foundIncidents recorded and linked to CAPA
14 Electronic signatureSame impact as handwritten; permanently linked; date and timeSignature records tied to the exact record version
15 Batch releaseOnly Qualified Persons certify release; e-signature can be usedRelease rights restricted to QP roles
16 Business continuityArrangements to keep critical processes running if systems failDocumented, tested fallback procedures
17 ArchivingArchived data stays accessible, readable and intact, including after system changesArchive retrieval tested after upgrades

Section 4 in practice: what validation evidence looks like

Section 4 is the longest and the one most often discussed in inspections. Reduced to a checklist:

  • An up-to-date inventory of GMP computerised systems and their functions.
  • User requirements that describe required functions, are based on risk, and trace through the life cycle.
  • Evidence that the supplier’s quality system and development work were assessed.
  • For bespoke systems, a process for formal assessment and reporting of quality and performance across the life cycle.
  • Test methods and scenarios that are shown to be appropriate, including limits and edge cases.
  • Data migration from other systems verified so values and meaning are not altered.

None of that is unique to the EU. It is the same life cycle described in our GxP software validation guide, and GAMP 5 is the common way of producing it.

Audit trails and e-signatures under Annex 11

Section 9 asks you to consider, based on risk, building in a system-generated record of all GMP-relevant changes and deletions. For a change or deletion of GMP-relevant data, the reason should be documented. Audit trails must be available, convertible to an intelligible form and regularly reviewed.

Section 14 says electronic signatures have the same impact as handwritten ones within the company, are permanently linked to their record, and include the date and time of signing. Our deep dive on audit trail requirements covers the design work in detail, and it applies to both rules.

Annex 11 vs 21 CFR Part 11

The two overlap heavily, and a system designed well for one covers most of the other. The differences are mostly in emphasis.

EU Annex 11 compared with US 21 CFR Part 11
TopicEU Annex 1121 CFR Part 11
Legal natureEU GMP guideline used by inspectorsUS federal regulation
ScopeAll computerised systems in GMP activitiesElectronic records and signatures required by predicate rules or submitted to FDA
Risk managementExplicit, across the life cycleNot in the rule text; risk-based approach set out in FDA guidance
SuppliersFormal agreements and risk-based supplier assessmentNot addressed directly
Audit trail reasonReason for change should be documentedNot stated in the rule; expected by data-integrity guidance
E-signaturesSame impact as handwritten, linked, datedDetailed rules on components, manifestation and certification to FDA
OperationsPeriodic evaluation, incidents, continuity, archivingMainly through validation, record protection and procedures

The clause-by-clause view of the US side is in our Part 11 checklist for LIMS.

The draft revision published in 2025

In July 2025 the European Commission and PIC/S released a revised draft of Annex 11 for public consultation, together with a revised Chapter 4 and a new Annex 22 on artificial intelligence. The draft is much longer than the 2011 text and goes further on topics such as life-cycle quality risk management, cloud and service providers, audit-trail review and identity and access management.

Cloud and SaaS systems under Annex 11

Annex 11 does not mention the cloud by name, but section 3 already covers it: when a service provider hosts or runs a GMP system, there should be a formal agreement setting out responsibilities, and the competence and reliability of the provider should be assessed based on risk. In practice that means a supplier assessment or audit, a quality agreement, clear rules on releases and change notification, backup and restore responsibilities, data location, and how data are returned at the end of the contract. The regulated company remains responsible for the system, wherever it runs.

Questions to ask a software supplier

  • Can you map each Annex 11 section to a feature or a document?
  • How is the audit trail stored, and can anyone change it?
  • How do backup and restore work, and how were they tested?
  • What does a quality or service agreement with you cover?
  • How are upgrades released, documented and impact-assessed?
  • How do we retrieve archived records after a version change?

We build regulated systems with these answers designed in, and our computer system validation service prepares Annex 11 and Part 11 deliverables for existing systems. To build the skills in-house, see our Software Validation course.

Frequently asked questions

What is EU GMP Annex 11?

Annex 11 is the part of the EU GMP guidelines, EudraLex Volume 4, that covers computerised systems used in GMP-regulated activities. It sets expectations for risk management, suppliers, validation, data integrity, security, change control and archiving.

Is Annex 11 the same as 21 CFR Part 11?

No, but they overlap heavily. Part 11 is a US regulation on electronic records and signatures. Annex 11 is an EU GMP guideline on computerised systems that also covers suppliers, risk management, periodic evaluation and business continuity.

Does Annex 11 apply to Indian pharma companies?

It applies when a company manufactures for the EU market or is inspected against EU or PIC/S GMP. Many Indian exporters therefore design their systems and procedures to meet Annex 11 as well as Part 11.

Does Annex 11 require a reason for change in the audit trail?

Yes. Section 9 says that for a change or deletion of GMP-relevant data the reason should be documented, and that audit trails should be available in an intelligible form and regularly reviewed.

Is there a new version of Annex 11?

A revised draft was published for public consultation in July 2025, alongside a revised Chapter 4 and a new Annex 22 on AI. Until a final version is adopted and takes effect, the 2011 text applies.

Does infrastructure need qualification under Annex 11?

Yes. The principle of Annex 11 states that IT infrastructure should be qualified, alongside validating the applications that run on it.

Call +91 79738 47707Chat on WhatsApp