Quick answer:
The validated state is the condition in which a computerized system consistently performs as intended and continues to meet documented GMP requirements. Validation establishes this state before go-live, while change control, incident management, supplier oversight, and periodic review ensure it is maintained throughout the system lifecycle.
Introduction
Imagine a laboratory information management system (LIMS) used to calculate the potency of a vaccine batch. At go-live, the calculation formula, transfer of instrument data, user permissions, and final report are validated. Months later, a vendor update changes the interface mapping, so the LIMS imports the first replicate result instead of the validated average of all replicates. The system does not crash, and the reported value still looks plausible. Yet the batch decision now relies on a calculation that no longer follows the approved method.
This is why EU GMP Annex 11 matters. A system can work correctly when first validated and still fall out of control as software, configurations, users, interfaces, suppliers, and security threats change. Annex 11 therefore covers two equally important stages: establishing control before implementation and maintaining the validated state after the system enters operation.
In this guide, we explain what Annex 11 is, which systems it covers, its main requirements, how it relates to GAMP 5 and FDA 21 CFR Part 11, and what compliance looks like in a modern cloud and software-as-a-service (SaaS) environment.
Key takeaways
What is EU GMP Annex 11?
EU GMP Annex 11 is the European Good Manufacturing Practice guideline for validating, operating, securing, and maintaining computerized systems used in GMP-regulated activities. It forms part of EudraLex Volume 4, the EU GMP Guide.
The current version, Revision 1, came into operation in June 2011. It states that the application should be validated and the supporting IT infrastructure qualified. It also establishes a fundamental principle: replacing a manual operation with a computerized system must not reduce product quality, process control, or quality assurance, or increase the overall risk of the process.
Annex 11 defines a computerized system as software and hardware components that together fulfill a function. In practice, the validated boundary also needs to account for the implemented configuration, interfaces, data, procedures, and users needed to perform the GMP function as intended.
Annex 11 applies to any computerized system used as part of a GMP-regulated activity, including systems that control a GMP process, create or store GMP records, perform critical calculations, support quality or batch-release decisions, or provide evidence of GMP compliance. Examples include eQMS, LIMS, MES, electronic batch records, laboratory instruments, environmental monitoring systems, and document or training platforms.
This means Annex 11 is not simply a software development standard. It is a control framework for ensuring that digitalization does not weaken GMP operations or the reliability of regulated records.
Why Annex 11 matters more than ever
Since 2011, pharmaceutical technology has changed dramatically. Cloud hosting, SaaS platforms, outsourced infrastructure, remote administration, automated interfaces, connected manufacturing systems, and frequent vendor-driven releases are now common.
In 2025, European regulators and PIC/S published a consultation draft to revise Annex 11 after nearly 15 years of technological change. The draft explicitly cites the evolving IT landscape, the growth of cloud services, and new technologies as reasons for the update.
The contrast between the two documents is significant. The current Annex is five pages long; the consultation draft extends to 19 pages and adds far more operational detail. The 2025 text remains a draft and does not replace the 2011 Annex. Even so, it identifies the areas in which regulators believe clearer and stronger controls are needed. The focus is moving from proving that a system was validated before use to demonstrating continuing control over the system, its data, users, suppliers, and security.
Current requirement and proposed direction
The key Annex 11 requirements explained
1. Ownership and risk management
Outsourcing an activity does not outsource accountability. Whether a system is supplied by a vendor, operated by internal IT, hosted in the cloud, or supported by qualified infrastructure, the regulated company must ensure that the implemented system and supporting evidence are appropriate for the intended GMP use.
The current Annex requires formal agreements with third parties, supplier assessment, and a risk-based decision on whether an audit is needed. The 2025 draft makes the principle even clearer: the regulated user remains fully responsible when relying on a vendor, service provider, or internal IT department.
Risk management determines how much validation and which data integrity controls are necessary. Those decisions must be justified and documented. A reminder notification and an automated calculation used for batch release should not receive the same validation effort because their potential impacts are different.
The 2025 draft explicitly places computerized systems used for GMP-related activities within the pharmaceutical quality system. It links their validation and operation with deviations, root cause analysis, CAPA effectiveness, internal audits, management review, quality metrics, and senior-management oversight. Digital system failures are therefore not merely IT issues; they are quality system issues.
Recommended learning:
cGMP compliance in pharma: what it is, requirements, and why it matters
2. System requirements, supplier control, and validation
Validation is not a one-time exercise performed before go-live and then forgotten. It begins by defining, in a User Requirements Specification (URS), what the organization expects the system to do and which GMP functions it will rely on.
A weak requirement might say, “The system shall manage CAPAs.” A testable requirement would define the expected control, for example: “Where segregation of duties is required, the system shall prevent the CAPA owner from approving the effectiveness check.”
The 2011 Annex requires the URS to describe required functions, reflect GMP impact, and remain traceable throughout the lifecycle. The 2025 draft adds operational, functional, data integrity, technical, interface, performance, availability, security, and regulatory requirements, and expects the chosen configuration to be documented.
These expectations apply to in-house, commercial, and SaaS systems. Vendor documentation and testing may be leveraged, but the regulated user must confirm that the evidence applies to the implemented version and test the company-specific configuration and critical GMP uses.
Supplier evidence can be leveraged, but responsibility cannot be transferred.
3. Data integrity, access, audit trails, and electronic signatures
Data integrity results from system design, accurate data capture, appropriate access, traceability, security, review, and responsible user behavior. Not from adding an audit trail after implementation.
The current Annex requires controls for critical manual entries, electronic data exchange, system access, audit trails, and electronic signatures. The 2025 draft proposes unique accounts, timely access changes, segregation of duties, recurrent access reviews, multifactor authentication for remote access to critical systems, access logs, inactivity logout, and account locking.
The distinction between current and proposed audit-trail requirements matters. The 2011 Annex asks organizations to consider audit trails, based on risk, for GMP-relevant changes and deletions. The 2025 draft would require automatic logging of relevant manual user interactions. The record should show who acted, what changed, the old and new values, when it changed, and why, while remaining protected, searchable, sortable, and subject to documented, risk-based review.
For electronic signatures, the current Annex requires an equivalent impact to a handwritten signature, a permanent link to the record, date and time. The draft adds full re-authentication when the signature is executed rather than relying only on the previous login.
4. Change control, incidents, and periodic review
A validated system rarely remains unchanged. Releases, configuration updates, patches, interfaces, infrastructure, and business processes evolve, and each change can affect the validated state.
The current Annex requires controlled changes and periodic evaluation. The 2025 draft expands periodic review to cover changes to hardware, software, configuration, infrastructure, interfaces, and documentation; cumulative and undocumented changes; deviations, incidents, CAPAs, audits, and inspections; access and audit-trail reviews; security events; supplier service-level agreements (SLAs) and key performance indicators (KPIs); backup and restore; archiving; data integrity assessments; and regulatory changes.
Validation gets the system into a controlled state. Change control, incident management, and periodic review keep it there.
5. Security, backup, continuity, and archiving
The 2011 Annex addresses security, backup, business continuity, and archiving through high-level principles. The 2025 draft treats cybersecurity as a direct GMP concern and adds detailed expectations for supported platforms, timely patching, network segmentation, firewalls, anti-malware protection, penetration testing for critical internet-facing systems, and encrypted remote connections.
The draft also requires risk-based backup frequency and retention, restore testing, and physical and logical separation from original data. Physical separation keeps the backup at a different location, so one fire, flood, or equipment failure is less likely to destroy both copies. Logical separation keeps the backup isolated from the same network and user access, reducing the risk that a cyberattack or accidental deletion affects both the live data and the backup.
For critical processes, the current Annex requires documented and tested alternatives for system downtime. Archiving must preserve more than a static report: the draft expects GMP data, metadata, and audit trails to remain protected, retrievable, and searchable throughout the retention period.
What Annex 11 compliance looks like in a modern SaaS eQMS
Before starting the process of implementing a cloud eQMS, the organization should define intended use, map the future GMP workflows, approve the URS and configuration, assess the provider, and assign responsibilities for validation, security, backup, incidents, releases, and support.
During validation, it should verify the configured implementation rather than relying only on generic vendor testing. Depending on risk, this may include approval workflows, user roles, electronic signatures, audit trails, reports, interfaces, error handling, and data export and retrieval.
After go-live, the organization must manage access changes, assess vendor releases, investigate incidents, monitor service performance, perform periodic reviews, and preserve an exit strategy for its GMP data.
For a SaaS system, the supplier agreement should state who performs each activity, how service performance is monitored through service-level agreements and key performance indicators, how incidents and new versions are communicated, what support is available during inspections, and how the regulated company will retrieve its data if the relationship ends. The company does not need to repeat every provider test, but it must understand and approve the evidence it relies on and test the GMP uses and configurations that remain its responsibility.
Annex 11, GAMP 5, and FDA 21 CFR Part 11: how do they work together?
These three frameworks are related, but they are not interchangeable.
How do Annex 11, FDA 21 CFR Part 11, and GAMP 5 differ?
EU GMP Annex 11, FDA 21 CFR Part 11, and GAMP 5 address computerized systems from different perspectives.
- EU GMP Annex 11 takes a broad lifecycle approach to computerized systems used in GMP-regulated environments, covering validation, operation, security, change control, data integrity, and ongoing system oversight.
- FDA 21 CFR Part 11 focuses specifically on the trustworthiness, reliability, and regulatory acceptance of electronic records and electronic signatures within its scope.
- GAMP 5 is not a regulation. It is industry guidance that provides a practical, risk-based framework for validating computerized systems and maintaining their validated state throughout the system lifecycle.
In simple terms, Annex 11 describes the level of control regulators expect, while GAMP 5 helps organizations establish and demonstrate those controls in practice. FDA 21 CFR Part 11 adds specific requirements for electronic records and electronic signatures where the regulation applies.
How to achieve Annex 11 compliance
The 2011 Annex separates its requirements into a project phase and an operational phase. The same distinction provides a practical compliance model.
Pre-implementation: project phase
-
1. Define scope, intended use, and ownership. Identify the GMP process, dependent records or decisions, and responsible parties.
-
2. Perform the risk assessment. Use product quality, patient safety, and data integrity risks to determine the validation strategy and controls.
-
3. Define system requirements. Approve the URS, critical data flows, interfaces, and configuration.
-
4. Assess suppliers and establish agreements. Evaluate competence, documentation, support, security, and the need for an audit.
-
5. Qualify and validate before use. Confirm installation and configuration, test critical requirements and risks, document deviations, and approve the system.
Post-implementation: operational phase
-
6. Control access and security. Grant, change, review, and revoke access in a timely manner.
-
7. Manage changes and supplier releases. Assess updates, patches, interfaces, and configuration changes before implementation.
-
8. Manage incidents, deviations, and CAPAs. Investigate failures, assess impact, address root causes, and verify effectiveness.
-
9. Operate data integrity controls. Maintain audit trails, signatures, accuracy checks, and controlled data transfers.
-
10. Test backup, restore, and downtime arrangements. Demonstrate that critical data can be recovered and critical processes supported.
-
11. Perform periodic review and supplier oversight. Confirm continued fitness for intended use and the validated state.
- 12. Control archiving, migration, and retirement. Preserve accessibility, readability, integrity, metadata, and audit trails.
Common Annex 11 compliance mistakes
From what I have seen, many weaknesses in how pharmaceutical companies comply with Annex 11 begin with a disconnect between approved documentation and daily operation.
Common examples include treating validation as a one-time project; using a generic URS that does not reflect the configured system; assuming supplier certification transfers responsibility; having an audit trail without an effective review process; running backups without demonstrating restoration; failing to adjust access after role changes; and applying updates without assessing GMP impact.
Conclusion
Annex 11 addresses both sides of the system lifecycle. Before implementation, the organization defines intended use, assigns ownership, assesses risks and suppliers, establishes requirements, qualifies infrastructure, and validates the system. After implementation, it maintains the validated state through access control, change management, incident handling, supplier oversight, data integrity controls, backup and restore testing, periodic review, and controlled archiving or retirement.
The 2025 draft shows where regulatory expectations are heading: greater accountability for regulated users, stronger control of cloud and SaaS providers, more explicit cybersecurity measures, more usable audit trails, and stronger protection and recovery of GMP data.
Keeping this evidence connected becomes difficult when requirements, validation records, supplier evidence, access reviews, changes, incidents, CAPAs, and periodic reviews are spread across spreadsheets, email, and separate repositories. A unified digital quality platform can make that traceability easier. Scilife’s Smart Quality platform can support connected workflows and records, but the regulated company remains responsible for defining, validating, and governing its intended use.
FAQs
What is EU GMP Annex 11?
EU GMP Annex 11 is the European GMP guideline for computerized systems used in pharmaceutical manufacturing and other GMP-regulated activities. It covers validation, risk management, suppliers, data integrity, security, audit trails, signatures, change control, periodic evaluation, backup, continuity, and archiving.
What is a computerized system under Annex 11?
A computerized system includes software and hardware that fulfill a function, together with the implemented configuration, interfaces, data, procedures, infrastructure, and users needed to perform the intended GMP function..
Which systems are subject to Annex 11?
All computerized systems used as part of GMP-regulated activities are in scope. Applicability depends on intended use and GMP impact, such as controlling a process, creating GMP records, performing critical calculations, or supporting release decisions.
Is Annex 11 legally binding?
Annex 11 forms part of the EU GMP Guide and represents an established regulatory expectation for organizations subject to EU GMP. Inspectors use it to assess whether systems are appropriately validated, controlled, and maintained.
What is the difference between Annex 11 and FDA 21 CFR Part 11?
Annex 11 addresses broader lifecycle control in EU GMP environments. FDA 21 CFR Part 11 focuses on electronic records and signatures within the scope of FDA rules.
Does Annex 11 require an audit trail?
The current 2011 version requires organizations to consider audit trails, based on risk, for GMP-relevant changes and deletions. The 2025 draft proposes more explicit requirements for automatic recording, protection, searchability, review, and availability.
Does Annex 11 apply to cloud and SaaS systems?
Yes, when the system is used in a GMP-regulated activity. Outsourcing hosting, testing, maintenance, or operation does not remove the regulated organization’s responsibility.
How often should computerized systems be periodically reviewed?
The interval should be justified according to risk. Criticality, complexity, changes, incidents, supplier releases, security exposure, and previous findings can influence frequency.
What changed in the 2025 Annex 11 draft?
The draft explicitly places computerized systems used for GMP-related activities within the pharmaceutical quality system. It also substantially expands expectations for lifecycle management, supplier and SaaS oversight, alarms, access management, audit trails, electronic signatures, cybersecurity, backup, and archiving. It does not replace the 2011 Annex, but it indicates the controls regulators want to make more explicit.




