Annex 11 — computerised systems
Annex 11 sets the GMP requirements for computerised systems used in regulated activities, covering the full lifecycle from supplier assessment and validation through operation, security and retirement.
Annex 11 sets the GMP requirements for computerised systems used in regulated activities, covering the full lifecycle from supplier assessment and validation through operation, security and retirement.
Plain-English explanation, then the primary regulation it comes from.
Understanding annex 11 — computerised systems
Annex 11 is structured around a lifecycle: a project phase covering risk management, personnel, suppliers and validation, then an operational phase covering data, accuracy checks, storage, printouts, audit trails, change and configuration management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity and archiving. Reading it as a checklist of that shape is the quickest way to find your gaps.
Risk management runs through the whole annex, which means the depth of everything else is a decision you must justify. A system whose failure could affect patient safety, product quality or data integrity warrants more validation, tighter access control and closer audit trail review than a system whose failure is merely inconvenient. Applying uniform rigour to everything is both expensive and, paradoxically, a way of under-controlling what matters.
Supplier and service provider management is explicit. Where third parties supply, install, configure, integrate, validate, maintain or host a system, formal agreements should exist, and supplier competence should be assessed — with audits based on risk. Cloud and hosted arrangements bring this sharply into focus, because the controls you rely on are largely someone else's.
Two operational requirements account for a disproportionate share of findings: audit trails that are enabled but never reviewed, and access control that has drifted so that leavers retain accounts and privileges exceed roles. Both are visible to an inspector within minutes and both suggest the system is not actually being managed.
- Risk-based throughout
- The extent of validation and controls is justified by the system's impact.
- Supplier assessment and agreements
- Formal agreements where third parties provide or host systems; competence assessed.
- Data and accuracy checks
- Critical data entered manually requires an additional check on accuracy.
- Audit trails
- Generated for GMP-relevant changes and deletions, and regularly reviewed.
- Security and access
- Access restricted to authorised persons; individual identities; privileges matched to role.
- Periodic evaluation
- Systems periodically evaluated to confirm they remain valid and compliant.
- Business continuity and archiving
- Provision for system unavailability, and archived data remaining readable and retrievable.
Common failure modes
- Leaver accounts still active, and privileges that exceed the role the person actually performs.
- Audit trail review with no named owner, no frequency and no record that it happened.
- Cloud or hosted systems with no agreement covering GMP responsibilities.
- Periodic evaluation never performed, so systems validated once drift for years unchecked.
Where this is written down
- European CommissionEudraLex Volume 4 — EU GMP guidelines
Annex 11 — Computerised Systems
- PIC/SPIC/S PI 041 — Good Practices for Data Management and Integrity
PI 041 for data governance expectations
- MHRAMHRA — GxP Data Integrity Guidance and Definitions
Read next
Computerised systems
ReadTechnicalData integrity
ReadTechnicalALCOA and ALCOA+
ReadTechnicalValidation
ReadLooking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.
Knowing the requirement is not the same as closing the gap
If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.