Computerised systems
A computerised system in GMP is the hardware, software and associated business process together — validated for its intended use, with the depth of validation driven by risk and by what the supplier has already demonstrated.
A computerised system in GMP is the hardware, software and associated business process together — validated for its intended use, with the depth of validation driven by risk and by what the supplier has already demonstrated.
Plain-English explanation, then the primary regulation it comes from.
Understanding computerised systems
Annex 11 applies to any computerised system used as part of a GMP-regulated activity, and the definition is broader than most inventories reflect. The system is not just the software: it is the software, the hardware it runs on, and the business process it supports. That is why validating a package in isolation, without reference to how the site actually uses it, misses the point.
Scope is where sites lose findings. LIMS, MES, ERP and chromatography data systems are always on the list. Spreadsheets performing GMP calculations, standalone instrument software, and small departmental databases usually are not — and all three are systems. An unvalidated spreadsheet computing a release calculation is a common and entirely avoidable finding.
Validation effort should be risk-based and should leverage supplier work rather than duplicate it. A documented supplier assessment can justify reducing the site's own testing for a widely used standard product, whereas configured or bespoke systems carry more of the burden locally. What cannot be delegated is verification that the system works for your intended use, with your configuration and your data.
Audit trails are the requirement most often half-implemented. Being enabled is necessary but not sufficient — Annex 11 expects them to be reviewed. An audit trail that nobody has ever looked at provides no assurance and is trivially easy for an inspector to test by asking who performs the review, how often, and what they found last time.
Hybrid paper-and-electronic arrangements need explicit treatment: which record is the raw data, how the two are reconciled, and how the paper element is controlled. Undefined hybrids are where data integrity gaps concentrate.
- System = software + hardware + process
- Validation covers intended use, not the package in the abstract.
- Complete inventory
- Including spreadsheets, instrument software and departmental databases.
- Risk-based, supplier-leveraged
- Documented supplier assessment can reduce, not remove, site testing.
- Audit trails reviewed
- Enabled, protected, and periodically reviewed by someone with a defined responsibility.
- Access control and roles
- Individual accounts, appropriate privileges, no shared logins for GMP actions.
- Periodic evaluation
- Systems re-evaluated to confirm they remain valid and compliant.
Common failure modes
- Spreadsheets performing GMP calculations, unvalidated and uncontrolled.
- Audit trails enabled but never reviewed, so the control exists only nominally.
- Shared or generic logins, which destroy attributability across every record the system holds.
- Hybrid systems where nobody has defined which record is the raw data.
Where this is written down
- European CommissionEudraLex Volume 4 — EU GMP guidelines
Annex 11 — Computerised Systems
- PIC/SPIC/S PI 041 — Good Practices for Data Management and Integrity
PI 041 on data governance for computerised systems
- MHRAMHRA — GxP Data Integrity Guidance and Definitions
On audit trail review and hybrid records
Read next
Annex 11 — computerised systems
ReadTechnicalData integrity
ReadTechnicalALCOA and ALCOA+
ReadTechnicalValidation
ReadLooking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.
Knowing the requirement is not the same as closing the gap
If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.