Technical · Validation & data

Computerised systems

A computerised system in GMP is the hardware, software and associated business process together — validated for its intended use, with the depth of validation driven by risk and by what the supplier has already demonstrated.

In one line

A computerised system in GMP is the hardware, software and associated business process together — validated for its intended use, with the depth of validation driven by risk and by what the supplier has already demonstrated.

Plain-English explanation, then the primary regulation it comes from.

Explanation

Understanding computerised systems

Annex 11 applies to any computerised system used as part of a GMP-regulated activity, and the definition is broader than most inventories reflect. The system is not just the software: it is the software, the hardware it runs on, and the business process it supports. That is why validating a package in isolation, without reference to how the site actually uses it, misses the point.

Scope is where sites lose findings. LIMS, MES, ERP and chromatography data systems are always on the list. Spreadsheets performing GMP calculations, standalone instrument software, and small departmental databases usually are not — and all three are systems. An unvalidated spreadsheet computing a release calculation is a common and entirely avoidable finding.

Validation effort should be risk-based and should leverage supplier work rather than duplicate it. A documented supplier assessment can justify reducing the site's own testing for a widely used standard product, whereas configured or bespoke systems carry more of the burden locally. What cannot be delegated is verification that the system works for your intended use, with your configuration and your data.

Audit trails are the requirement most often half-implemented. Being enabled is necessary but not sufficient — Annex 11 expects them to be reviewed. An audit trail that nobody has ever looked at provides no assurance and is trivially easy for an inspector to test by asking who performs the review, how often, and what they found last time.

Hybrid paper-and-electronic arrangements need explicit treatment: which record is the raw data, how the two are reconciled, and how the paper element is controlled. Undefined hybrids are where data integrity gaps concentrate.

What it requiresThe substance of the requirement, stated plainly.
System = software + hardware + process
Validation covers intended use, not the package in the abstract.
Complete inventory
Including spreadsheets, instrument software and departmental databases.
Risk-based, supplier-leveraged
Documented supplier assessment can reduce, not remove, site testing.
Audit trails reviewed
Enabled, protected, and periodically reviewed by someone with a defined responsibility.
Access control and roles
Individual accounts, appropriate privileges, no shared logins for GMP actions.
Periodic evaluation
Systems re-evaluated to confirm they remain valid and compliant.
Where it goes wrongThe part a definition alone will not tell you.

Common failure modes

  • Spreadsheets performing GMP calculations, unvalidated and uncontrolled.
  • Audit trails enabled but never reviewed, so the control exists only nominally.
  • Shared or generic logins, which destroy attributability across every record the system holds.
  • Hybrid systems where nobody has defined which record is the raw data.
Primary sourcesAlways verify against the primary source before acting; guidance is revised.

Where this is written down

Related

Read next

Looking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.

Applying this to your site

Knowing the requirement is not the same as closing the gap

If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.